CVE-2026-21889

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

23 Jan 2026, 14:49

Type Values Removed Values Added
CPE cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Weblate
Weblate weblate
CWE NVD-CWE-noinfo
References () https://github.com/WeblateOrg/weblate/commit/a6eb5fd0299780eca286be8ff187dc2d10feec47 - () https://github.com/WeblateOrg/weblate/commit/a6eb5fd0299780eca286be8ff187dc2d10feec47 - Patch
References () https://github.com/WeblateOrg/weblate/pull/17516 - () https://github.com/WeblateOrg/weblate/pull/17516 - Issue Tracking
References () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3g2f-4rjg-9385 - () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3g2f-4rjg-9385 - Patch, Vendor Advisory

14 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 17:16

Updated : 2026-01-23 14:49


NVD link : CVE-2026-21889

Mitre link : CVE-2026-21889

CVE.ORG link : CVE-2026-21889


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo