PYSEC-2026-3942
Dashboard / Vulnerabilities / PYSEC-2026-3942
PYSEC-2026-3942
Summary: Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Details: ### Impact The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. ### Patches * https://github.com/WeblateOrg/weblate/pull/19970 ### References Parts of this issue were independently reported by four reporters: * @H3xV0rT3x via GitHub * [imhego](https://hackerone.com/imhego) via HackerOne * [v01demort](https://hackerone.com/v01demort) via HackerOne * [b4nder](https://hackerone.com/b4nder) via HackerOne
References: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-2q2q-jr9g-v9rf, https://nvd.nist.gov/vuln/detail/CVE-2026-55228, https://github.com/WeblateOrg/weblate/pull/19970, https://github.com/WeblateOrg/weblate/commit/19babc99b05f2cc299b5090f90f79d8181f25d79, https://github.com/WeblateOrg/weblate, https://pypi.org/project/weblate, https://github.com/advisories/GHSA-2q2q-jr9g-v9rf
Affected packages
Package
Name: weblate
Purl: pkg:pypi/weblate
Affected ranges
Type: ECOSYSTEM
Events:
