CVE-2026-33212
Gravedad CVSS v3.1:
BAJA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
15/04/2026
Última modificación:
15/04/2026
Descripción
*** Pendiente de traducción *** Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brute-force the random UUID of the task, so exploiting this is unlikely with the default API rate limits. This issue has been fixed in version 5.17.
Impacto
Puntuación base 3.x
3.10
Gravedad 3.x
BAJA



