PatchSiren cyber security CVE debrief
CVE-2026-55228 WeblateOrg CVE debrief
CVE-2026-55228 is a high-severity vulnerability in Weblate, a web-based continuous localization platform. In versions prior to 2026.7, the REST API did not properly enforce team scopes, allowing users to submit invalid team configurations and potentially expose private projects, permitting unauthorized translation, repository, and project-management operations.
- Vendor
- WeblateOrg
- Product
- weblate
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-09
Who should care
Weblate administrators, users with project or workspace-scoped teams, and security teams responsible for managing access controls and monitoring API activity should assess exposure and verify configurations.
Why it matters
CVE-2026-55228 is a high-severity vulnerability in Weblate that could allow unauthorized access to private projects and operations. Defenders should prioritize verifying configurations, reviewing team scopes, and ensuring proper API access controls.
- Potential exposure of private projects
- Unauthorized translation, repository, and project-management operations
- Need for verification of Weblate versions and configurations
- Importance of reviewing team scopes and permissions
Technical summary
The Weblate REST API did not properly enforce team scopes in versions prior to 2026.7, allowing users to submit invalid team configurations. This could expose private projects and permit unauthorized translation, repository, and project-management operations. The vulnerability impacts Weblate administrators, users with project or workspace-scoped teams, and security teams responsible for managing access controls and monitoring API activity. Defenders should prioritize verifying configurations, reviewing team scopes, and ensuring proper API access controls.
Defensive priority
Defenders should prioritize verifying Weblate versions and configurations, reviewing team scopes and permissions, and ensuring proper API access controls.
Recommended defensive actions
- Verify Weblate version and configuration
- Review team scopes and permissions
- Ensure proper API access controls
- Monitor for suspicious API activity
- Perform vulnerability scanning
- Implement additional logging
- Review access controls for Weblate instances
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. However, additional information on exploitation or affected systems is limited. Defenders should verify Weblate versions and configurations, review team scopes and permissions, and ensure proper API access controls. The REST API did not properly enforce team scopes, allowing users to submit invalid team configurations. This could expose private projects and permit unauthorized translation, repository, and project-management operations
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55228 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55228
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55228 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55228
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WeblateOrg/weblate/commit/19babc99b05f2cc299b5090f90f79d8181f25d79
-
Source reference
Unverified legacy reference
URL: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-2q2q-jr9g-v9rf
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.