CVE-2026-77508

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's mailbox. This issue is fixed in version 2026.8.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-26 20:18

Updated : 2026-09-09 21:09


NVD link : CVE-2026-77508

Mitre link : CVE-2026-77508

CVE.ORG link : CVE-2026-77508


JSON object : View

Products Affected

No product.

CWE
CWE-302

Authentication Bypass by Assumed-Immutable Data

CWE-841

Improper Enforcement of Behavioral Workflow