{"id":"CVE-2026-21889","aliases":["GHSA-3g2f-4rjg-9385","PYSEC-2026-2037"],"url":"https://o3.security/vulnerability/CVE-2026-21889","summary":"Weblate leaks information via screenshots","details":"### Impact\nThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename.\n\n### Patches\n* https://github.com/WeblateOrg/weblate/pull/17516\n\n### References\n\nThanks to Lukas May and Michael Leu for reporting this.","published":"2026-01-14T16:28:30.208Z","modified":"2026-08-12T03:51:09.502849214Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"weblate","fixedVersion":"5.15.2"}],"fix":{"url":"https://github.com/WeblateOrg/weblate/commit/a6eb5fd0299780eca286be8ff187dc2d10feec47","label":"WeblateOrg/weblate@a6eb5fd"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21889.json"},{"type":"ADVISORY","url":"https://github.com/WeblateOrg/weblate/security/advisories/GHSA-3g2f-4rjg-9385"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21889"},{"type":"FIX","url":"https://github.com/WeblateOrg/weblate/commit/a6eb5fd0299780eca286be8ff187dc2d10feec47"},{"type":"FIX","url":"https://github.com/WeblateOrg/weblate/pull/17516"},{"type":"PACKAGE","url":"https://github.com/WeblateOrg/weblate"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.502849214Z"}}