VDB
CVE-2026-27457
CVE-2026-27457
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This allows any authenticated user (or anonymous users if `REQUIRE_LOGIN` is not set) to list and retrieve ALL addons across all projects and components via `GET /api/addons/` and `GET /api/addons/{id}/`. Version 5.16.1 fixes the issue.
EPSS 0.30% · 22.6th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.30%
22.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | weblate | 0, 0, 0 |
| weblate | weblate | 0, 0, 0 |
| WeblateOrg | weblate | < 5.16.1, *, < 5.16.1 |
Timeline
- Feb 26, 2026 CVE Published
- Feb 26, 2026 PoC Published
- Feb 26, 2026 PoC Published
- Feb 27, 2026 CVE Updated
- Feb 27, 2026 EPSS Score
- Mar 1, 2026 EPSS Score
- Mar 2, 2026 EPSS Score
- Mar 4, 2026 EPSS Score
- Mar 5, 2026 EPSS Score
- Mar 7, 2026 EPSS Score
- Mar 9, 2026 EPSS Score
- Mar 9, 2026 Security Advisory
References
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.16.1 fix
- https://github.com/WeblateOrg/weblate/commit/3f58f9a4152bc0cbdd6eff5954f9c7bc4d9f0af9 fix
- https://github.com/WeblateOrg/weblate/pull/18164 fix
- https://github.com/WeblateOrg/weblate/commit/7802c9b121eb407c48d4adddd4f2458fb3efef0f fix
- https://github.com/WeblateOrg/weblate/pull/18107 fix
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-wppc-7cq7-cgfv patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-27457 advisory
- https://github.com/WeblateOrg/weblate package