CVE-2026-92803
LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated fi
CVSS
5.3
Medium
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Sep 16, 2026 · Last modified: Sep 22, 2026 · CWE-862
0.4%EPSS · 30 days0.4%
2026-09-172026-09-23
LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without authentication on protected instances.
- github.comhttps://github.com/LibreTranslate/LibreTranslate
- github.comhttps://github.com/LibreTranslate/LibreTranslate/blob/v1.9.6/libretranslate/app.py#L1029-L1030
- github.comhttps://github.com/LibreTranslate/LibreTranslate/issues/1012
- www.vulncheck.comhttps://www.vulncheck.com/advisories/libretranslate-through-1.9.6-missing-access-check-on-the-download-file-route
- github.comhttps://github.com/LibreTranslate/LibreTranslate/issues/1012
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-956047.5 HIG—
——0Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.5hCVE-2026-955276.5 MED—
——0Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.5hCVE-2026-955137.5 HIG—
——0Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.5hCVE-2026-946795.4 MED—
——0Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.5hCVE-2026-944986.5 MED—
——0Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.5hCVE-2026-940805.3 MED—
——0Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.5h