CVE-2026-32251Disclosure(tolgee / tolgee)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch tolgee tolgee systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resources (.xml) and .resx files don't disable external entity processing. An authenticated user who can import translation files into a project can exploit this to read arbitrary files from the server and make server-side requests to internal services. This vulnerability is fixed in 3.166.3.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tolgee

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-12); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
tolgee

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-12: 3Mentions · 2026-04-08: 2PoC Mentioned / Linked · 2026-03-12: 1PoC Mentioned / Linked · 2026-04-08: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 3Technical Details · 2026-04-08: 203-1204-08
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-123
Disclosure2Patch1
2026-04-082
Disclosure2
Full discourse5 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    Reading /etc/ passwd via translation file upload in Tolgee's cloud platform (CVE-2026-32251, CVSS 9.3) https://simonkoeck.com/writeups/tolgee-xxe-translation-import

    Post summary

    The post discloses an XXE vulnerability (CVE‑2026‑32251) that allows reading /etc/passwd in Tolgee’s cloud platform, includes a high CVSS score, and links to a writeup containing a PoC, but no evidence of active exploitation or patches.

    0201382.0K
    157.2K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Tolgee XML translation import vulnerable to XXE allowing arbitrary file read via CVE-2026-32251 — attackers can upload crafted translation files to read /etc/passwd, environment secrets, or cloud metadata credentials, impacting multi-tenant deployments until parser security was fixed. https://simonkoeck.com/writeups/tolgee-xxe-translation-import

    Post summary

    The post announces a CVE-2026-32251 exploit in Tolgee's XML translation import that permits arbitrary file reads via XXE; a proof of concept is linked to a writeup.

    0000082
    2.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-32251 Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resources (.xml) and .resx files don't disable extern… https://www.cve.org/CVERecord?id=CVE-2026-32251

    Post summary

    The post highlights that Tolgee’s XML parsing before version 3.166.3 fails to disable external entities, implying a vulnerability that is likely addressed in 3.166.3.

    00000137
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32251 XML External Entity (XXE) Vulnerability in Tolgee Localization Platform ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32251 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces the discovery of an XML External Entity (XXE) vulnerability (CVE‑2026‑32251) in the Tolgee Localization Platform and provides links to detailed notes, but it contains no PoC, exploit, or patch information.

    0000020
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32251: Tolgee has an XXE Injection in T... XXE in translation imports = instant server filesystem access and SSRF against internal services - classic XML parser f... https://zerodaysignal.com/vulnerability/CVE-2026-32251 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces the discovery of CVE-2026-32251, a server-side XSS vulnerability in Tolgee that allows filesystem access and SSRF, with a link presumably containing a PoC but no active exploitation or patch info.

    0000068
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptolgeetolgee---

Explore more