MEDIUM
LibreTranslate
CVE published 2026-09-16
CVE-2026-92803
CVE-2026-92803 debrief: LibreTranslate 1.9.6 download_file route has no access check, allowing unauthenticated file downloads. This CVE was published on 2026-09-16T21:17:29.970Z and was last modified on 2026-09-22T20:53:07.383Z. The vulnerability allows attackers to bypass API key requirements and abuse ban lists to download files without authentication on protected instances. Defenders should assess expo [truncated]