CVE-2026-33214

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by blocking access to /api/memory/ in the HTTP server, which removes access to this feature.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

21 Apr 2026, 14:11

Type Values Removed Values Added
First Time Weblate
Weblate weblate
References () https://github.com/WeblateOrg/weblate/pull/18513 - () https://github.com/WeblateOrg/weblate/pull/18513 - Issue Tracking, Patch
References () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-mpf5-3vph-q75r - () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-mpf5-3vph-q75r - Mitigation, Patch, Vendor Advisory
CPE cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

15 Apr 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-15 18:17

Updated : 2026-04-21 14:11


NVD link : CVE-2026-33214

Mitre link : CVE-2026-33214

CVE.ORG link : CVE-2026-33214


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-862

Missing Authorization