<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aweblateweblate/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 21:15:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aweblateweblate/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>IDOR Vulnerability in Weblate GroupViewSet API</title><link>https://feed.craftedsignal.io/briefs/2026-08-weblate-idor/</link><pubDate>Fri, 28 Aug 2026 21:15:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-weblate-idor/</guid><description>An Insecure Direct Object Reference vulnerability (CVE-2026-55228) in the Weblate GroupViewSet API allows authenticated project managers to gain unauthorized read access to private projects via manipulated team configurations.</description><content:encoded><![CDATA[<p>Weblate, an open-source translation tool, is affected by a security vulnerability (CVE-2026-55228) in the GroupViewSet API. This Insecure Direct Object Reference (IDOR) flaw permits an authenticated user with project manager privileges to bypass existing authorization controls. By submitting requests that manipulate project- and workspace-scoped team configurations, attackers can misconfigure project access rights. This action results in unauthorized read access to private projects that the user would otherwise be restricted from viewing. The vulnerability affects all versions of Weblate prior to 2026.7. Defenders should prioritize patching, as this vulnerability allows for the unauthorized exfiltration of sensitive translation project data within multi-tenant or multi-project environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation grants unauthorized read access to sensitive private projects. In environments where multiple teams share a Weblate instance, this allows project managers to potentially view proprietary intellectual property or sensitive documentation stored within private translation projects. No estimate of victim count is provided, but the vulnerability impacts all organizations self-hosting Weblate versions below 2026.7.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Weblate instances to version 2026.7 or later to resolve the underlying API logic flaw in GroupViewSet.</li>
<li>Review audit logs for unusual API requests directed at the GroupViewSet endpoints that involve project-scoped team modifications.</li>
<li>Restrict project manager privileges to trusted users until patches can be applied to minimize the window of opportunity for privilege abuse.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>idor</category><category>api-vulnerability</category><category>access-control</category></item></channel></rss>