Sploitus

CVE-2026-24126

4 known exploits for CVE-2026-24126

Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.

Affected products
Weblate
Weblate
< 5.16
Fix
Available
CVSS 3.1
9.1 CRITICAL
EPSS
0.4% (37th percentile)
Weakness
CWE-88
NVD status
Analyzed
Published
2026-02-18
CVE-2026-24126 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2026-24126

Proof-of-concept code and exploit modules indexed by Sploitus