
CVE-2026-33220 Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper acce… https://www.cve.org/CVERecord?id=CVE-2026-33220
Post summary
CVE-2026-33220 discloses an access-control flaw in Weblate’s translation memory API before V5.17, with no evidence of exploitation, PoC, or patch availability provided.
