CVE-2026-21889 PUBLISHED

Weblate leaks information via screenshots

Assigner: GitHub_M
Reserved: 05.01.2026 Published: 14.01.2026 Updated: 14.01.2026

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor WeblateOrg
Product weblate
Versions
  • Version < 5.15.2 is affected

References

Problem Types

  • CWE-284: Improper Access Control CWE