PatchSiren cyber security CVE debrief
CVE-2026-61790 WeblateOrg CVE debrief
CVE-2026-61790 is a medium-severity vulnerability in Weblate, a web-based continuous localization platform. The issue allows users to receive site-wide global permissions without configuring two-factor authentication (2FA), even if their team enforces 2FA for other permission levels. This discrepancy could lead to unintended access to sensitive areas, such as the site management interface. The vulnerability is fixed in Weblate version 2026.7.
- Vendor
- WeblateOrg
- Product
- weblate
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-09
Who should care
Weblate administrators and users with global permissions should assess their 2FA configurations to ensure proper enforcement and prevent unauthorized access. This includes verifying that 2FA is enforced for all users with site-wide permissions and reviewing compensating controls for exposed systems. Additionally, operators and security teams should review the vulnerability's impact on their Weblate deployments and prioritize remediation efforts.
Why it matters
CVE-2026-61790 is a medium-severity vulnerability in Weblate that allows users to receive global permissions without 2FA, potentially leading to unauthorized access. Defenders should prioritize verifying 2FA enforcement and ensure proper configuration to prevent exploitation.
- Defenders must verify 2FA configuration for users with global permissions to prevent unauthorized access.
- Inconsistent 2FA enforcement may lead to unintended access to sensitive areas like the site management interface.
- Proper 2FA configuration is necessary to ensure the security of Weblate deployments.
Technical summary
The vulnerability occurs because Weblate does not enforce 2FA requirements consistently across different permission levels. Specifically, while team permissions may require 2FA, global permissions do not. This inconsistency allows users to obtain global permissions without 2FA, potentially granting them access to sensitive areas like the site management interface at /manage/. The issue is fixed in version 2026.7. Defenders should prioritize verifying 2FA enforcement for Weblate users with global permissions and ensure proper configuration to prevent unauthorized access.
Defensive priority
Defenders should prioritize verifying 2FA enforcement for Weblate users with global permissions and ensure proper configuration to prevent unauthorized access.
Recommended defensive actions
- Verify 2FA configuration for Weblate users with global permissions
- Ensure 2FA is enforced for all users with site-wide permissions
- Update Weblate to version 2026.7 or later
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 2026.7. However, additional information on potential exploitation or affected deployments is limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61790 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61790
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61790 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61790
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WeblateOrg/weblate/commit/89042ab12268842655ddc10cb052bfc4dfa7a589
-
Source reference
Unverified legacy reference
URL: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-x86c-ff69-cr2m
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.