CVE-2026-86035
Received Received - Intake

Argument Injection in Weblate Mercurial Backend

Vulnerability report for CVE-2026-86035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
weblate weblate to 2026.7.1 (inc)
weblate weblate 2026.8
weblate weblate From 4.11.1 (inc) to 2026.7.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86035 is a high-severity argument-injection vulnerability in Weblate versions 4.11.1 through 2026.7.1. It occurs when repository filenames start with a hyphen (-), which Mercurial interprets as command-line options instead of file paths. An authenticated user with project-scoped component.edit permission could exploit this via a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account.

Detection Guidance

To detect this vulnerability, check Weblate versions running on your system. Versions 4.11.1 through 2026.7.1 are vulnerable. Run: weblate --version or check the Weblate admin interface for version details. Also inspect Mercurial-backed components for RESX files with repository paths starting with hyphens (-).

Commands to check: grep -r "weblate" /path/to/weblate/version or weblate shell -c "import weblate; print(weblate.__version__)"

Impact Analysis

This vulnerability allows an attacker to execute arbitrary commands on the system running Weblate with the privileges of the Weblate service account. This could lead to unauthorized data access, modification, or deletion, as well as potential disruption of service. The impact depends on the permissions of the Weblate service account.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, which may violate compliance requirements such as GDPR (data protection) or HIPAA (health information privacy). Organizations using affected Weblate versions may face regulatory penalties or reputational damage if exploited.

Mitigation Strategies

Upgrade Weblate to version 2026.8 or later immediately. Remove the Update RESX files add-on from Mercurial-backed components. Reject repository paths beginning with hyphens in your VCS settings. Restrict component.edit permissions to trusted users only.

Alternatively, migrate affected components away from Mercurial to mitigate the risk of command injection through this vector.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart