Vulnerability Description
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weblate | Weblate | < 5.15.2 |
Related Weaknesses (CWE)
References
- https://github.com/WeblateOrg/weblate/commit/a6eb5fd0299780eca286be8ff187dc2d10fPatch
- https://github.com/WeblateOrg/weblate/pull/17516Issue Tracking
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3g2f-4rjg-9385PatchVendor Advisory
FAQ
What is CVE-2026-21889?
CVE-2026-21889 is a vulnerability with a CVSS score of 7.5 (HIGH). Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to acce...
How severe is CVE-2026-21889?
CVE-2026-21889 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-21889?
Check the references section above for vendor advisories and patch information. Affected products include: Weblate Weblate.