CVE-2026-77508 LOW

CVE-2026-77508: Weblate: Unverified REST API email changes

Vendor Weblateorg
Product weblate
Weakness CWE-302
Published August 26, 2026
Last update August 27, 2026

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's mailbox. This issue is fixed in version 2026.8.

Key dates

02Disclosure timeline

August 26, 2026 CVE published
August 27, 2026 Record updated