CVE-2026-33214: medium-severity vulnerability in WeblateOrg weblate
Weblate has improper access control for the translation memory API
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by blocking access to /api/memory/ in the HTTP server, which removes access to this feature.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
WeblateOrg · weblateRelated CVEs — WeblateOrg weblate
In the same product, most dangerous first.
CVE-2026-33435HIGHWeblate: Remote code execution during backup restorationEPSS 0.9%CVE-2025-68398CRITICALWeblate has git config file overwrite vulnerability that leads to remote code executionEPSS 0.8%CVE-2022-24710MEDIUMCross-site Scripting in WeblateEPSS 0.8%CVE-2026-61792HIGHWeblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)EPSS 0.6%CVE-2026-34393HIGHWeblate: Privilege escalation in the user API endpointEPSS 0.5%CVE-2026-34242HIGHWeblate: Arbitrary File Read via SymlinkEPSS 0.5%