Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's mailbox. This issue is fixed in version 2026.8. | |
| Title | Weblate: Unverified REST API email changes | |
| Weaknesses | CWE-302 CWE-841 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-27T14:32:57.362Z
Reserved: 2026-08-20T20:23:02.506Z
Link: CVE-2026-77508
Updated: 2026-08-27T13:53:12.367Z
Status : Received
Published: 2026-08-26T20:18:01.843
Modified: 2026-08-27T17:20:23.417
Link: CVE-2026-77508
No data.
OpenCVE Enrichment
Updated: 2026-08-26T21:45:03Z