CVE-2026-55228: Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55228 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →