CVE-2026-34393

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
15/04/2026
Last modified:
21/04/2026

Description

Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* 5.17 (excluding)