Weblate: Privilege escalation in the user API endpoint
Description
Published by the National Vulnerability Database
Apr 15, 2026
Published to the GitHub Advisory Database
Apr 16, 2026
Reviewed
Apr 16, 2026
Last updated
Apr 16, 2026
Impact
The user patching API endpoint didn't properly limit the scope of edits.
Patches
References
Thanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this.
References