CVE-2026-21889

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-14 17:16

Updated : 2026-01-23 14:49


NVD link : CVE-2026-21889

Mitre link : CVE-2026-21889

CVE.ORG link : CVE-2026-21889


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo