SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-55228

HIGH · CVSS 8.1 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects Weblate's REST API in versions prior to 2026.7, where improper enforcement of project and workspace team scopes allows unauthorized users to submit invalid configurations. This could lead to unauthorized access to private projects, enabling malicious actions such as translation and project management beyond intended permissions. Organizations using Weblate for software localization should prioritize upgrading to version 2026.7 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55228
Severity
HIGH
CVSS
8.1
EPSS
0.23%

Original NVD Description

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not authorized to see or manage. This could expose private projects and permit translation, repository, and project-management operations outside the user's intended permission scope. This issue is fixed in version 2026.7.