CVE-2026-61790: Weblate: Team-enforced 2FA is bypassed for global permissions

Published Aug 26, 2026
·
Updated

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for site-wide global permissions. As a result, a user who belongs to a team that enforces 2FA and grants a global permission still receives that global permission even without 2FA configured, while the same requirement is correctly applied to project-, component-, and workspace-scoped permissions. Such a user can act on the granted global permission, including reaching the site management interface at /manage/. This issue is fixed in version 2026.7.

Affected Software

1 affected component
Weblate weblate<2026.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Weblate to a version that resolves this vulnerability.

    Fixed in 2026.7

Event History

Aug 26, 2026
CVE Published
via MITRE·08:23 PM
Data Sourced
via MITRE·08:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments are affected if they use a version prior to 2026.7 and have a team that both enforces two-factor authentication and grants site-wide global permissions to its members. Project-, component-, and workspace-scoped permissions are not affected by this bypass.

2

What does an attacker need to exploit the bypass?

The attacker must already have a user account that belongs to a team enforcing 2FA and that receives a global permission through that team. They can use the global permission without configuring 2FA, potentially including access to the /manage/ site management interface when that permission allows it.

3

How can administrators determine whether they are already affected?

Review teams that require 2FA and identify whether they assign any global permissions. Check whether members of those teams have not configured 2FA but can still exercise the assigned global permissions or access /manage/.

4

What can be done before upgrading?

Remove or avoid granting global permissions through teams that enforce 2FA, and review existing team members for missing 2FA enrollment. Use project-, component-, or workspace-scoped permissions where appropriate, since those scopes correctly enforce the team 2FA requirement.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203