CVE-2026-34393: Weblate: Privilege escalation in the user API endpoint
Impact
The user patching API endpoint didn't properly limit the scope of edits.
Patches https://github.com/WeblateOrg/weblate/pull/18687
References Thanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this.
Other sources
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34393?
CVE-2026-34393 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2026-34393?
To fix CVE-2026-34393, upgrade to Weblate version 5.17 or later.
What is the impact of CVE-2026-34393 on users?
CVE-2026-34393 allows unauthorized users to escalate their privileges through the user API endpoint.
Which versions of Weblate are affected by CVE-2026-34393?
CVE-2026-34393 affects Weblate versions prior to 5.17.
Is there a workaround for CVE-2026-34393?
There is no known workaround for CVE-2026-34393; upgrading to the fixed version is recommended.