Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without authentication on protected instances. | |
| Title | LibreTranslate through 1.9.6 Missing Access Check on the download_file Route | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:53.271Z
Reserved: 2026-09-16T19:47:14.191Z
Link: CVE-2026-92803
No data.
Status : Received
Published: 2026-09-16T21:17:29.970
Modified: 2026-09-16T21:17:29.970
Link: CVE-2026-92803
No data.
OpenCVE Enrichment
No data.