CVE-2026-55228
Received Received - Intake

Weblate REST API Team Scope Validation Bypass

Vulnerability report for CVE-2026-55228, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: GitHub, Inc.

Description

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not authorized to see or manage. This could expose private projects and permit translation, repository, and project-management operations outside the user's intended permission scope. This issue is fixed in version 2026.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
weblate weblate 2026.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Weblate versions before 2026.7. The REST API fails to properly validate team scopes for project and workspace assignments. Users can submit invalid team configurations, granting unauthorized access to projects they should not manage or view. This allows them to perform restricted operations like translations or repository changes.

Detection Guidance

To detect this vulnerability, check the version of Weblate running on your system. If it is prior to 2026.7, the system is vulnerable. Run commands like 'weblate --version' or check the version via the Weblate admin interface or API endpoints.

Impact Analysis

If exploited, an attacker with limited access could escalate privileges to view or modify private projects. This may lead to unauthorized translations, repository changes, or project management actions. Sensitive data in projects could be exposed or altered without proper authorization.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using affected Weblate versions may fail compliance audits due to insufficient access restrictions.

Mitigation Strategies

Immediately upgrade Weblate to version 2026.7 or later. Review team assignments and project access permissions to ensure no unauthorized access has occurred. Audit API logs for suspicious team configuration changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55228. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart