CVE-2026-77508

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's mailbox. This issue is fixed in version 2026.8.

Scoring

Severity
LOW
CVSS base score
3.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
EPSS probability
0.15%
CWE
CWE-302, CWE-841
Published
2026-08-26
Last modified
2026-08-27

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs