CVE-2026-86035

🟡 Monitoruj

Wstrzyknięcie argumentów w Weblate pozwala na wykonanie dowolnych poleceń przez uwierzytelnionego użytkownika.

CVSS
8.5
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-09-29 15:17:30 UTC
Ostatnia modyfikacja (NVD)2026-10-02 13:18:01 UTC
Referencje