Authorization bypass through user-controlled key in Tolgee - #VU133248

 

Authorization bypass through user-controlled key in Tolgee - #VU133248

Published: June 2, 2026


Vulnerability identifier: #VU133248
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify translation suggestions in another project or disclose sensitive information.

The vulnerability exists due to authorization bypass through user-controlled key in the translation suggestion handling endpoints when processing suggestion operations with a foreign suggestion identifier after validating only the local key context. A remote user can send a specially crafted request to modify translation suggestions in another project or disclose sensitive information.

The accept operation can copy the victim suggestion text into the attacker's project.


Affected software

Tolgee

Remediation

Install security update from vendor's website.

Tolgee - update to 3.194.0

External References

Related Security Bulletins