CVE-2026-21889: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-21889 is an improper access control vulnerability in Weblate, a web-based localization tool, that allows unauthenticated users to access screenshot images by guessing their filenames. All versions prior to 5.15.2 are affected. The vulnerability was disclosed on January 14, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 7.5 (High) as assessed by NVD, and a CVSS v4.0 base score of 2.3 (Low) as assessed by the CNA (GitHub) (GitHub Advisory).

Technical details

The root cause is CWE-284 (Improper Access Control): screenshot images were served directly by the HTTP server (e.g., via a /media/ path) without any authentication or authorization checks, bypassing Weblate's application-level access controls entirely. An attacker with network access only needs to guess or enumerate the filename of a screenshot to retrieve it via a direct HTTP GET request — no credentials or user interaction are required. The fix, implemented in PR #17516, introduces a Django proxy view (ScreenshotView) that enforces access control checks before serving image content, and removes the direct /media/ static file serving configuration from nginx and Apache examples (GitHub Advisory, Fix PR, Fix Commit).

Impact

Successful exploitation allows unauthenticated remote attackers to view screenshot images stored in a Weblate instance, which may contain sensitive localization project data, internal communications, user interface content, or other confidential information captured in those images. The impact is limited to confidentiality — there is no integrity or availability impact. There is no evidence of lateral movement potential, but exposure of project screenshots could reveal sensitive business or product information to unauthorized parties (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.045% (0.000450), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).

Exploitation steps

  1. Reconnaissance: Identify a publicly accessible Weblate instance running a version prior to 5.15.2 using web search, Shodan, or Censys. Confirm the version via the Weblate about page or HTTP response headers.
  2. Identify the media path: Determine the base URL for screenshot media files, typically served under /media/screenshots/ based on Weblate's default configuration.
  3. Enumerate or guess filenames: Screenshot filenames in Weblate are typically generated with a UUID or similar pattern. An attacker could attempt to enumerate filenames using wordlists, brute-force tools, or by leveraging any publicly visible screenshot references in the application's HTML.
  4. Retrieve screenshots: Send unauthenticated HTTP GET requests directly to the media URL (e.g., GET /media/screenshots/<filename>.png) to retrieve screenshot images without any authentication challenge.
  5. Analyze retrieved content: Review the downloaded screenshots for sensitive project data, internal UI content, or other confidential information (GitHub Advisory, Fix PR).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP GET requests to /media/screenshots/ paths on the Weblate server, particularly with sequential or randomized filename patterns; high volume of 200 OK responses to /media/ paths from external or unknown IP addresses.
  • Logs: Web server access logs (nginx/Apache) showing repeated requests to /media/screenshots/ from unauthenticated sessions or unfamiliar source IPs; requests with no referrer header targeting screenshot file paths directly.
  • File System: No direct file system artifacts expected from read-only exploitation; however, review of media directory access timestamps may reveal unexpected access patterns.

Mitigation and workarounds

Upgrade Weblate to version 5.15.2 or later, which replaces direct HTTP server serving of screenshot images with a Django proxy view that enforces proper access control. As an interim workaround if immediate upgrade is not possible, restrict access to the /media/ path at the web server or firewall level to prevent unauthenticated external access. After upgrading, administrators should also remove the /media/ location block from their nginx or Apache configuration files, as it is no longer needed and its presence could re-expose files (GitHub Advisory, Fix Commit).

Community reactions

The vulnerability was reported by security researchers Lukas May and Michael Leu and was fixed by the Weblate maintainer (nijel) prior to public disclosure, following responsible disclosure practices. The advisory was rated Low severity by the CNA based on CVSS v4.0 scoring, though NVD independently assessed it as High (7.5) under CVSS v3.1. No significant broader media coverage or notable community debate has been observed (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management