PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61790 WeblateOrg CVE debrief

CVE-2026-61790 is a medium-severity vulnerability in Weblate, a web-based continuous localization platform. The issue allows users to receive site-wide global permissions without configuring two-factor authentication (2FA), even if their team enforces 2FA for other permission levels. This discrepancy could lead to unintended access to sensitive areas, such as the site management interface. The vulnerability is fixed in Weblate version 2026.7.

Vendor
WeblateOrg
Product
weblate
CVSS
MEDIUM 4.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-09
Advisory published
2026-08-26
Advisory updated
2026-09-09

Who should care

Weblate administrators and users with global permissions should assess their 2FA configurations to ensure proper enforcement and prevent unauthorized access. This includes verifying that 2FA is enforced for all users with site-wide permissions and reviewing compensating controls for exposed systems. Additionally, operators and security teams should review the vulnerability's impact on their Weblate deployments and prioritize remediation efforts.

Why it matters

CVE-2026-61790 is a medium-severity vulnerability in Weblate that allows users to receive global permissions without 2FA, potentially leading to unauthorized access. Defenders should prioritize verifying 2FA enforcement and ensure proper configuration to prevent exploitation.

  • Defenders must verify 2FA configuration for users with global permissions to prevent unauthorized access.
  • Inconsistent 2FA enforcement may lead to unintended access to sensitive areas like the site management interface.
  • Proper 2FA configuration is necessary to ensure the security of Weblate deployments.

Technical summary

The vulnerability occurs because Weblate does not enforce 2FA requirements consistently across different permission levels. Specifically, while team permissions may require 2FA, global permissions do not. This inconsistency allows users to obtain global permissions without 2FA, potentially granting them access to sensitive areas like the site management interface at /manage/. The issue is fixed in version 2026.7. Defenders should prioritize verifying 2FA enforcement for Weblate users with global permissions and ensure proper configuration to prevent unauthorized access.

Defensive priority

Defenders should prioritize verifying 2FA enforcement for Weblate users with global permissions and ensure proper configuration to prevent unauthorized access.

Recommended defensive actions

  • Verify 2FA configuration for Weblate users with global permissions
  • Ensure 2FA is enforced for all users with site-wide permissions
  • Update Weblate to version 2026.7 or later
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 2026.7. However, additional information on potential exploitation or affected deployments is limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61790 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61790

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61790 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61790

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.