PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62249 WeblateOrg CVE debrief

CVE-2026-62249 is a vulnerability in Weblate, a web-based continuous localization platform. An authenticated user with access to a project can retrieve the change history of restricted components in that project through nested API change endpoints, even without permission to view those components directly. The issue allows unauthorized access to sensitive component change history, potentially exposing restricted component identities, translation and unit links, and change payload fields. This issue is fixed in version 2026.7. Defenders should assess exposure and apply the fix to prevent unauthorized access.

Vendor
WeblateOrg
Product
weblate
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-09
Advisory published
2026-08-26
Advisory updated
2026-09-09

Who should care

Defenders responsible for Weblate instances, particularly those with authenticated users having project access, should assess exposure and apply the fix to prevent unauthorized access to sensitive component change history.

Why it matters

CVE-2026-62249 is a medium-severity vulnerability in Weblate that allows authenticated users to access restricted component change history. Defenders should prioritize verifying exposure and applying the fix to prevent potential unauthorized access and data exposure.

  • Potential unauthorized access to sensitive component change history
  • Possible enumeration of changes for components that should be hidden from users
  • Exposure of restricted component identities, translation and unit links, and change payload fields

Technical summary

The vulnerability allows an authenticated user with access to a project to retrieve the change history of restricted components in that project through nested API change endpoints, even without permission to view those components directly. The exposed data can include the restricted component's identity, translation and unit links, and change payload fields such as source or translated string content. This issue is fixed in version 2026.7, and defenders should prioritize verifying exposure and applying the fix to prevent potential unauthorized access and data exposure.

Defensive priority

Defenders should prioritize verifying exposure and applying the fix, as this vulnerability allows unauthorized access to sensitive component change history.

Recommended defensive actions

  • Verify if Weblate instances are exposed to authenticated users with project access
  • Check if the fixed version 2026.7 has been applied
  • Restrict access to sensitive component change history
  • Monitor for unauthorized access attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. The vulnerability allows an authenticated user with access to a project to retrieve the change history of restricted components through nested API change endpoints. Evidence is limited to public sources, and defenders should verify exposure and apply the fix. The CVE Program and NVD offer official details, while additional source references provide further information on the fix and vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-62249 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-62249

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-62249 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62249

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.