CVE-2026-33214

MEDIUM

Weblate has improper access control for the translation memory API

Title source: cna
STIX 2.1

Description

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by blocking access to /api/memory/ in the HTTP server, which removes access to this feature.

Scores

CVSS v3 4.3
EPSS 0.0001
EPSS Percentile 1.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
pypi/weblate 0 - 5.17PyPI
weblate/weblate < 5.17
WeblateOrg/weblate < 5.17
Published Apr 15, 2026
Tracked Since Apr 15, 2026