CVE-2026-21889

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:19

Type Values Removed Values Added
Summary
  • (es) Weblate es una herramienta de localización basada en web. Antes de la versión 5.15.2, las imágenes de las capturas de pantalla eran servidas directamente por el servidor HTTP sin un control de acceso adecuado. Esto podría permitir a un usuario no autenticado acceder a las capturas de pantalla después de adivinar su nombre de archivo. Esta vulnerabilidad está corregida en la versión 5.15.2.

23 Jan 2026, 14:49

Type Values Removed Values Added
CPE cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Weblate
Weblate weblate
CWE NVD-CWE-noinfo
References () https://github.com/WeblateOrg/weblate/commit/a6eb5fd0299780eca286be8ff187dc2d10feec47 - () https://github.com/WeblateOrg/weblate/commit/a6eb5fd0299780eca286be8ff187dc2d10feec47 - Patch
References () https://github.com/WeblateOrg/weblate/pull/17516 - () https://github.com/WeblateOrg/weblate/pull/17516 - Issue Tracking
References () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3g2f-4rjg-9385 - () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3g2f-4rjg-9385 - Patch, Vendor Advisory

14 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 17:16

Updated : 2026-06-17 10:19


NVD link : CVE-2026-21889

Mitre link : CVE-2026-21889

CVE.ORG link : CVE-2026-21889


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo