
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21889 is an improper access control vulnerability in Weblate, a web-based localization tool, that allows unauthenticated users to access screenshot images by guessing their filenames. All versions prior to 5.15.2 are affected. The vulnerability was disclosed on January 14, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 7.5 (High) as assessed by NVD, and a CVSS v4.0 base score of 2.3 (Low) as assessed by the CNA (GitHub) (GitHub Advisory).
The root cause is CWE-284 (Improper Access Control): screenshot images were served directly by the HTTP server (e.g., via a /media/ path) without any authentication or authorization checks, bypassing Weblate's application-level access controls entirely. An attacker with network access only needs to guess or enumerate the filename of a screenshot to retrieve it via a direct HTTP GET request — no credentials or user interaction are required. The fix, implemented in PR #17516, introduces a Django proxy view (ScreenshotView) that enforces access control checks before serving image content, and removes the direct /media/ static file serving configuration from nginx and Apache examples (GitHub Advisory, Fix PR, Fix Commit).
Successful exploitation allows unauthenticated remote attackers to view screenshot images stored in a Weblate instance, which may contain sensitive localization project data, internal communications, user interface content, or other confidential information captured in those images. The impact is limited to confidentiality — there is no integrity or availability impact. There is no evidence of lateral movement potential, but exposure of project screenshots could reveal sensitive business or product information to unauthorized parties (GitHub Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.045% (0.000450), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
/media/screenshots/ based on Weblate's default configuration.GET /media/screenshots/<filename>.png) to retrieve screenshot images without any authentication challenge./media/screenshots/ paths on the Weblate server, particularly with sequential or randomized filename patterns; high volume of 200 OK responses to /media/ paths from external or unknown IP addresses./media/screenshots/ from unauthenticated sessions or unfamiliar source IPs; requests with no referrer header targeting screenshot file paths directly.Upgrade Weblate to version 5.15.2 or later, which replaces direct HTTP server serving of screenshot images with a Django proxy view that enforces proper access control. As an interim workaround if immediate upgrade is not possible, restrict access to the /media/ path at the web server or firewall level to prevent unauthenticated external access. After upgrading, administrators should also remove the /media/ location block from their nginx or Apache configuration files, as it is no longer needed and its presence could re-expose files (GitHub Advisory, Fix Commit).
The vulnerability was reported by security researchers Lukas May and Michael Leu and was fixed by the Weblate maintainer (nijel) prior to public disclosure, following responsible disclosure practices. The advisory was rated Low severity by the CNA based on CVSS v4.0 scoring, though NVD independently assessed it as High (7.5) under CVSS v3.1. No significant broader media coverage or notable community debate has been observed (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."