CVE-2026-24126Disclosure(weblate / weblate)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weblate

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
weblate

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-19: 2Mentions · 2026-02-24: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-24: 102-1902-24
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure2
2026-02-241
General1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-24126 📊 Severity: 6.6 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-24126 #CVE-2026-24126 #CVE #Medium #CyberSecurity #InfoSec https://t.co/en4I6qgxOa

    Post summary

    The tweet announces a new CVE (CVE‑2026‑24126) with a medium severity rating, but provides no technical details, PoC, exploit code, or patch information.

    0001039
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24126 Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lea… https://www.cve.org/CVERecord?id=CVE-2026-24126

    Post summary

    The text references CVE-2026-24126, noting a lack of input validation in Weblate's SSH console before version 5.16.0, but provides no further details on exploitation, patches, or PoC.

    00000200
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24126 SSH Host Key Argument Injection Vulnerability in Weblate Before 5.16.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24126

    Post summary

    The text announces CVE‑2026‑24126 as an SSH Host Key Argument Injection flaw in Weblate versions before 5.16.0, but provides no PoC, exploit, patch, or active exploitation details.

    0000088
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appweblateweblate---

Explore more