
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67715 is an improper access control vulnerability in Weblate, a web-based localization tool, that allows authenticated low-privileged users to enumerate all users or retrieve user notification settings via the REST API. It affects all Weblate versions prior to 5.15 and was disclosed on December 15, 2025. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Github Advisory, Weblate Advisory).
The root cause is insufficient authorization enforcement in Weblate's REST API endpoints, classified as CWE-284 (Improper Access Control) and CWE-285 (Improper Authorization). The API failed to properly restrict user search results to authenticated users and did not enforce access controls on the user notification settings endpoint, allowing any authenticated user to query these resources regardless of their privilege level. The fix, implemented in pull request #17256, introduced an allow_self parameter to permission checks, restricted user search to authenticated users only, and enforced proper authorization on notification endpoints (Weblate PR #17256, Github Advisory).
Successful exploitation allows any authenticated user with low privileges to enumerate all user accounts registered in the Weblate instance and access notification settings for arbitrary users. This exposes usernames, account metadata, and notification preferences, which can be leveraged for targeted phishing, credential stuffing, or reconnaissance in preparation for further attacks. There is no integrity or availability impact; the vulnerability is limited to confidentiality (Weblate Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (2nd percentile), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a valid (low-privilege) account on the target Weblate instance (Github Advisory).
curl -H "Authorization: Token <your_token>" https://<weblate-host>/api/users//api/users/ endpoint. In vulnerable versions, the response returns a list of all registered users regardless of the requester's privilege level./api/users/<username>/notifications/ for any user to retrieve their notification configuration, which may reveal additional account details./api/users/ or /api/users/<username>/notifications/ from a single authenticated user or IP address, especially iterating over multiple usernames./api/users/ endpoint by a low-privilege account; requests to notification endpoints for users other than the requester.Upgrade Weblate to version 5.15 or later, which enforces proper authorization on the user listing and notification settings API endpoints. No configuration-based workaround is available for unpatched versions; upgrading is the only effective remediation. As an interim measure, administrators should review API access logs for unusual enumeration activity and consider restricting API access to trusted networks where feasible (Weblate Advisory, Weblate PR #17256).
The vulnerability was responsibly disclosed by Hector Ruiz Ruiz and NaxusAI, and the Weblate maintainer (nijel) promptly addressed it with a patch merged on December 10, 2025, ahead of the public advisory on December 15, 2025. No significant broader media coverage or notable community debate has been observed beyond the standard advisory publication (Weblate Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."