Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
History

Wed, 14 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 17:00:00 +0000

Type Values Removed Values Added
Description Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
Title Weblate leaks information via screenshots
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-14T16:58:35.235Z

Reserved: 2026-01-05T17:24:36.929Z

Link: CVE-2026-21889

cve-icon Vulnrichment

Updated: 2026-01-14T16:58:31.320Z

cve-icon NVD

Status : Received

Published: 2026-01-14T17:16:07.940

Modified: 2026-01-14T17:16:07.940

Link: CVE-2026-21889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.