CVE-2026-27457General(weblate / weblate)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch weblate weblate systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This allows any authenticated user (or anonymous users if `REQUIRE_LOGIN` is not set) to list and retrieve ALL addons across all projects and components via `GET /api/addons/` and `GET /api/addons/{id}/`. Version 5.16.1 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weblate

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
weblate

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-26: 1Mentions · 2026-02-27: 2Mentions · 2026-03-09: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-02-27: 2Technical Details · 2026-03-09: 102-2602-2703-09
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-261
General1
2026-02-272
Disclosure1General1
2026-03-091
Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security patch for #openSUSE Tumbleweed: weblate 5.16.1-1.1 fixes CVE-2026-27457 (info disclosure). Read more: 👉 https://tinyurl.com/4d6ktz6v #Security https://t.co/ln1YtKx55V

    Post summary

    The tweet announces a critical patch for Weblate on openSUSE Tumbleweed that addresses CVE-2026-27457, an info disclosure vulnerability.

    0000051
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27457 Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = http://Addon.objects.al… https://www.cve.org/CVERecord?id=CVE-2026-27457

    Post summary

    A new vulnerability (CVE-2026-27457) in Weblate’s REST API is disclosed with code details, but no PoC, exploit, or patch information is provided.

    00000145
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27457 Weblate REST API Unauthorized Addon Information Disclosure Before 5.16.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27457

    Post summary

    The post references a Weblate REST API vulnerability that allows unauthorized addon information disclosure in versions before 5.16.1, but it does not provide details on exploits, active use, or remediation.

    0000042
    4.0K followersView on X
  • cvereports@_cvereports
    General

    CVE-2026-27457: Lost in Translation: Exposing Secrets via Weblate's Addon API In the world of automated localization, Weblate is a heavyweight champion, managing translations for thousands of open-source and commercial projects. However, a lapse in ac... https://cvereports.com/reports/CVE-2026-27457

    Post summary

    The text references CVE-2026-27457, indicating a potential secret exposure via Weblate's Addon API, but provides no further technical, exploit, or mitigation details.

    0000038
    32 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appweblateweblate---

Explore more