CVE-2026-27457

MEDIUM4.3EPSS 0.04%

Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

Published: 2/26/2026Modified: 2/28/2026

Description

### Impact Users were able to obtain add-on configuration via API. ### Patches * https://github.com/WeblateOrg/weblate/pull/18107 * https://github.com/WeblateOrg/weblate/pull/18164 ### References Weblate thanks @lighthousekeeper1212 for responsible disclosure.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (8)