CVE-2026-27457
MEDIUMWeblate < 5.16.1 - Unauthorized Addon Information Exposure via REST API
Title source: llmDescription
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This allows any authenticated user (or anonymous users if `REQUIRE_LOGIN` is not set) to list and retrieve ALL addons across all projects and components via `GET /api/addons/` and `GET /api/addons/{id}/`. Version 5.16.1 fixes the issue.
References (6)
Core 6
Core References
Vendor Advisory x_refsource_confirm
https://github.com/WeblateOrg/weblate/security/advisories/GHSA-wppc-7cq7-cgfv
Issue Tracking x_refsource_misc
https://github.com/WeblateOrg/weblate/pull/18107
Issue Tracking x_refsource_misc
https://github.com/WeblateOrg/weblate/pull/18164
Patch x_refsource_misc
https://github.com/WeblateOrg/weblate/commit/3f58f9a4152bc0cbdd6eff5954f9c7bc4d9f0af9
Patch x_refsource_misc
https://github.com/WeblateOrg/weblate/commit/7802c9b121eb407c48d4adddd4f2458fb3efef0f
Release Notes x_refsource_misc
https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.16.1
Scores
CVSS v3
4.3
EPSS
0.0030
EPSS Percentile
21.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
CWE-862
Status
published
Products (2)
pypi/weblate
0 - 5.16.1PyPI
weblate/weblate
< 5.16.1
Published
Feb 26, 2026
Tracked Since
Feb 27, 2026