CVE-2026-21889

HIGH

Weblate < 5.15.2 - Improper Access Control

Title source: rule
STIX 2.1

Description

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
pypi/weblate 0 - 5.15.2PyPI
weblate/weblate < 5.15.2
Published Jan 14, 2026
Tracked Since Feb 18, 2026