CVE-2026-86035: Weblate: Mercurial argument injection via repository filenames allows authenticated command execution

Published Sep 29, 2026
·
Updated

Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.

Affected Software

1 affected component
Weblate weblate>=4.11.1<=2026.7.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Weblate to a version that resolves this vulnerability.

    Fixed in 2026.8

Event History

Sep 29, 2026
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to exploitation?

Affected deployments are Weblate versions 4.11.1 through 2026.7.1 that use a Mercurial-backed RESX component with the Update RESX files add-on. The attacker must have an authenticated account with project-scoped component.edit permission.

2

What access and conditions does an attacker need?

An attacker needs component.edit permission in the relevant project and must be able to introduce a repository filename beginning with a hyphen. Exploitation is triggered when a later repository update causes Mercurial to interpret that filename as an option.

3

What is the impact of successful exploitation?

A successful exploit can execute arbitrary commands with the privileges of the Weblate service account. The vulnerability can therefore affect confidentiality, integrity, and availability beyond the compromised project scope.

4

What version resolves the issue?

The issue is patched in Weblate version 2026.8. Systems running versions from 4.11.1 through 2026.7.1 are affected according to the provided data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203