
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22251 is an insecure API key configuration vulnerability in wlc, the Weblate command-line client for Weblate's REST API. Prior to version 1.17.0, wlc allowed API keys to be specified in an unscoped manner (e.g., in the [weblate] section of the configuration file), rather than being bound to a specific server URL. This design flaw could cause the API key to be leaked to unintended servers. The vulnerability was disclosed on January 12, 2026, and affects all wlc versions before 1.17.0. It carries a CVSS v3.1 base score of 5.3 (Medium) per the CNA (GitHub), or 5.5 (Medium) per NVD (GitHub Advisory, Feedly).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Historically, wlc supported placing API keys in the [weblate] section or arbitrary configuration sections without binding them to a specific API URL. The get_url_key() method in wlc/config.py would read the key from the [weblate] section first, and only fall back to the URL-scoped [keys] section if no key was found there. This meant that if a user had an unscoped key configured, it could be sent to any server the client connected to — including unintended or malicious ones. The fix (PR #1098, commit aafdb50) refactored get_url_key() to exclusively read keys from the [keys] section using the API URL as the lookup key, and introduced cli_key/cli_url attributes for command-line overrides (GitHub Advisory, GitHub PR).
Successful exploitation could result in the disclosure of a user's Weblate API key to an unauthorized or malicious server, compromising confidentiality of authentication credentials. An attacker who obtains the leaked API key could use it to authenticate to the legitimate Weblate instance and perform actions on behalf of the victim, such as modifying translation projects or accessing sensitive project data. There is no integrity or availability impact directly from this vulnerability itself (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The vulnerability requires local access, low privileges, and user interaction (per the CNA CVSS vector), making it relatively difficult to exploit opportunistically. The EPSS score is approximately 0.011% (0.000110), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The issue was responsibly reported via HackerOne by researcher 'wh1zee' (GitHub Advisory, Feedly).
wlc is installed and configured checks the user's wlc configuration file (e.g., ~/.config/weblate or weblate.ini) for an unscoped API key set in the [weblate] section.url setting in the configuration (or uses a malicious project-level .weblate config file in a directory the victim uses) to point to an attacker-controlled server.wlc command (e.g., wlc list-projects) in a directory containing the malicious configuration.Authorization header.[weblate] section (e.g., key = <value>) of ~/.config/weblate, ~/.config/weblate.ini, or any project-level .weblate/weblate.ini file — rather than in the [keys] section keyed by URL.wlc to unexpected or unknown API endpoints containing an Authorization header with a Weblate API key.Upgrade wlc to version 1.17.0 or later, which enforces that API keys must be specified in the [keys] section of the configuration file, scoped to a specific API URL. As an immediate workaround without upgrading, remove any unscoped key = entries from the [weblate] section (or other non-[keys] sections) of the configuration file, and migrate keys to the [keys] section using the format <API_URL> = <KEY>. For example: [keys] https://hosted.weblate.org/api/ = APIKEY (GitHub Advisory, GitHub PR).
The vulnerability was reported to the Weblate team via HackerOne by researcher 'wh1zee' and was addressed promptly by maintainer 'nijel' in PR #1098, merged on January 7, 2026, ahead of the public disclosure on January 12, 2026. The fix was also accompanied by documentation updates to remove references to the deprecated key configuration pattern. No significant broader media coverage or notable community debate has been observed beyond standard vulnerability tracking (GitHub Advisory, GitHub PR).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."