CVE-2026-92803
LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated fi
CVSS
5.3
Medio
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Publicado: 16 sept 2026 · Última mod.: 22 sept 2026 · CWE-862
0.4%EPSS · 30 días0.4%
2026-09-172026-09-23
LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without authentication on protected instances.
- github.comhttps://github.com/LibreTranslate/LibreTranslate
- github.comhttps://github.com/LibreTranslate/LibreTranslate/blob/v1.9.6/libretranslate/app.py#L1029-L1030
- github.comhttps://github.com/LibreTranslate/LibreTranslate/issues/1012
- www.vulncheck.comhttps://www.vulncheck.com/advisories/libretranslate-through-1.9.6-missing-access-check-on-the-download-file-route
- github.comhttps://github.com/LibreTranslate/LibreTranslate/issues/1012
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-956047.5 ALT—
——0Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.6hCVE-2026-955276.5 MED—
——0Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.6hCVE-2026-955137.5 ALT—
——0Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.6hCVE-2026-946795.4 MED—
——0Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.6hCVE-2026-944986.5 MED—
——0Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.6hCVE-2026-940805.3 MED—
——0Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.6h