Résumé
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Détails de l’avis
Impact
The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.
Patches
References
Parts of this issue were independently reported by four reporters:
Références
- https://github.com/advisories/GHSA-2q2q-jr9g-v9rf
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-2q2q-jr9g-v9rf
- https://nvd.nist.gov/vuln/detail/CVE-2026-55228
- https://github.com/WeblateOrg/weblate/pull/19970
- https://github.com/WeblateOrg/weblate/commit/19babc99b05f2cc299b5090f90f79d8181f25d79
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-63735
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
- MEDIUMCVE-2026-72802
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
- MEDIUMCVE-2026-63669
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
- HIGHCVE-2026-73841
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
- MEDIUMCVE-2026-82395
Sulu: Media move/update authorization bypass (IDOR)
- HIGHCVE-2026-81892
EasyAdmin custom-action dispatcher bypasses access_control on other routes