CVE-2026-86035: Weblateorg Weblate

High severity, CVSS 8.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.

Affected products

  • Weblateorg Weblate: from 4.11.1, before 2026.8 (fixed in 2026.8)

Published 2026-09-29. Last modified 2026-10-02.