CVE-2026-34393

Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

21 Apr 2026, 14:05

Type Values Removed Values Added
CPE cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
First Time Weblate
Weblate weblate
References () https://github.com/WeblateOrg/weblate/pull/18687 - () https://github.com/WeblateOrg/weblate/pull/18687 - Issue Tracking, Patch
References () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3382-gw9x-477v - () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3382-gw9x-477v - Third Party Advisory

15 Apr 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-15 19:16

Updated : 2026-04-21 14:05


NVD link : CVE-2026-34393

Mitre link : CVE-2026-34393

CVE.ORG link : CVE-2026-34393


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-269

Improper Privilege Management