PatchSiren cyber security CVE debrief
CVE-2026-62249 WeblateOrg CVE debrief
CVE-2026-62249 is a vulnerability in Weblate, a web-based continuous localization platform. An authenticated user with access to a project can retrieve the change history of restricted components in that project through nested API change endpoints, even without permission to view those components directly. The issue allows unauthorized access to sensitive component change history, potentially exposing restricted component identities, translation and unit links, and change payload fields. This issue is fixed in version 2026.7. Defenders should assess exposure and apply the fix to prevent unauthorized access.
- Vendor
- WeblateOrg
- Product
- weblate
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for Weblate instances, particularly those with authenticated users having project access, should assess exposure and apply the fix to prevent unauthorized access to sensitive component change history.
Why it matters
CVE-2026-62249 is a medium-severity vulnerability in Weblate that allows authenticated users to access restricted component change history. Defenders should prioritize verifying exposure and applying the fix to prevent potential unauthorized access and data exposure.
- Potential unauthorized access to sensitive component change history
- Possible enumeration of changes for components that should be hidden from users
- Exposure of restricted component identities, translation and unit links, and change payload fields
Technical summary
The vulnerability allows an authenticated user with access to a project to retrieve the change history of restricted components in that project through nested API change endpoints, even without permission to view those components directly. The exposed data can include the restricted component's identity, translation and unit links, and change payload fields such as source or translated string content. This issue is fixed in version 2026.7, and defenders should prioritize verifying exposure and applying the fix to prevent potential unauthorized access and data exposure.
Defensive priority
Defenders should prioritize verifying exposure and applying the fix, as this vulnerability allows unauthorized access to sensitive component change history.
Recommended defensive actions
- Verify if Weblate instances are exposed to authenticated users with project access
- Check if the fixed version 2026.7 has been applied
- Restrict access to sensitive component change history
- Monitor for unauthorized access attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. The vulnerability allows an authenticated user with access to a project to retrieve the change history of restricted components through nested API change endpoints. Evidence is limited to public sources, and defenders should verify exposure and apply the fix. The CVE Program and NVD offer official details, while additional source references provide further information on the fix and vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-62249 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-62249
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-62249 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62249
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WeblateOrg/weblate/commit/a27b02110ab33995bce8cf9ea0eeddf72aa334ca
-
Source reference
Unverified legacy reference
URL: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-92m8-wv36-prmx
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.