CVE-2026-61790
Received Received - Intake

Two-Factor Authentication Bypass in Weblate

Vulnerability report for CVE-2026-61790, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: GitHub, Inc.

Description

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for site-wide global permissions. As a result, a user who belongs to a team that enforces 2FA and grants a global permission still receives that global permission even without 2FA configured, while the same requirement is correctly applied to project-, component-, and workspace-scoped permissions. Such a user can act on the granted global permission, including reaching the site management interface at /manage/. This issue is fixed in version 2026.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
weblate weblate 2026.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Weblate before version 2026.7 has a flaw where team-enforced two-factor authentication (2FA) requirements do not apply to global permissions. Users in teams with 2FA enforcement can still receive and use global permissions without enabling 2FA, potentially accessing sensitive site management features.

Detection Guidance

Check Weblate version with command: weblate --version. If version is prior to 2026.7, the system is vulnerable. Review team settings for 2FA enforcement and compare with global permissions granted.

Impact Analysis

If you are a user in a team that enforces 2FA, an attacker could exploit this to gain unauthorized access to global permissions and site management interfaces without your knowledge. This could allow them to perform administrative actions on your Weblate instance.

Compliance Impact

The vulnerability allows users without enforced two-factor authentication (2FA) to access global permissions, including site management interfaces. This could lead to unauthorized administrative access, potentially compromising data integrity and confidentiality. For GDPR, this may violate principles of data protection by design and default. For HIPAA, it could risk unauthorized access to protected health information.

Mitigation Strategies

Upgrade Weblate to version 2026.7 or later immediately. Verify that all team members have 2FA configured before granting any permissions, especially global ones. Audit existing global permissions to ensure only users with 2FA have access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61790. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart