# CVE-2026-77508

## Summary

- **CVE ID:** CVE-2026-77508
- **Severity:** LOW
- **CVSS Score:** 3.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
- **CWE:** CWE-302, CWE-841
- **Published:** Aug 26, 2026
- **Last Modified:** Aug 27, 2026

## Description

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's mailbox. This issue is fixed in version 2026.8.

## Affected Products

- WeblateOrg — weblate (< 2026.8)

## References

- [CNA](https://github.com/WeblateOrg/weblate/security/advisories/GHSA-x84p-6892-473c)
- [CNA](https://github.com/WeblateOrg/weblate/pull/20639)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._