CVE-2026-77508
CVE-2026-77508 is a low-severity vulnerability with a CVSS 3.x base score of 3.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-302.
Key facts
- Severity: Low (CVSS 3.x base score 3.5)
- EPSS exploit prediction: 0% (16th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-302
- Published:
- Last modified:
Description
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's mailbox. This issue is fixed in version 2026.8.
Frequently asked questions
- What is CVE-2026-77508?
- Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's mailbox. This issue is fixed in version 2026.8.
- How severe is CVE-2026-77508?
- CVE-2026-77508 has a CVSS 3.x base score of 3.5, rated low severity. It is exploitable over network with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-77508 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (16th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-77508?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-77508 published?
- CVE-2026-77508 was published on 2026-08-26 and last updated on 2026-09-09.
References
- https://github.com/WeblateOrg/weblate/pull/20639
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-x84p-6892-473c
Other CWE-302 vulnerabilities
- CVE-2026-48781 — Critical (CVSS 9.9): Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an…
- CVE-2024-56404 — Critical (CVSS 9.9): In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows…
- CVE-2024-43441 — Critical (CVSS 9.8): Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache…
- CVE-2025-47158 — Critical (CVSS 9.0): Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges…
- CVE-2024-12838 — High (CVSS 8.8): The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass…
- CVE-2026-5423 — High (CVSS 8.2): @neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT…