CVE-2026-86035 Details
Description
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8.
A vulnerability allowing argument injection has been identified in the Mercurial backend of Weblate, a web-based localization platform. This issue affects Weblate versions 4.11.1 through 2026.7.1. The vulnerability arises because repository filenames that begin with a dash can be misinterpreted as Mercurial options rather than as literal paths. An authenticated user with project-scoped component.edit permission could exploit this vulnerability through a Mercurial-backed RESX component, using the Update RESX files add-on. This exploitation could lead to the execution of arbitrary commands, with the Weblate service account's privileges, during a subsequent repository update. This vulnerability is a residual issue from an incomplete fix for CVE-2022-23915.
Weblate has released a patch for this vulnerability in version 2026.8. Users should upgrade to Weblate 2026.8 or later. After upgrading, repository filenames will be correctly handled as literal paths, preventing the argument injection. For those unable to upgrade immediately, it is recommended to remove the Update RESX files add-on from Mercurial-backed components, reject component templates and tracked repository paths that begin with a dash, and restrict component.edit permission to trusted users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/WeblateOrg/weblate/commit/f60a9759a6d851bd10ccdefe9b1b7f0cdb9e9bbd | [email protected] | Source CodeVendor |
| https://github.com/WeblateOrg/weblate/pull/20768 | [email protected] | Source CodeVendor |
| https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.8 | [email protected] | Release NotesVendor |
| https://github.com/WeblateOrg/weblate/security/advisories/GHSA-327h-qqgm-qv55 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Weblate | >= 4.11.1, <= 2026.7.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion