CVE-2026-55228 affects Weblate, a web-based continuous localization platform for managing software translations. In versions prior to 2026.7, the REST API failed to properly enforce the scope of project- and workspace-scoped teams. This allowed authenticated users to submit invalid team configurations through the API, effectively assigning projects to teams without proper authorization checks. Exploiting this flaw could allow users to gain access to private projects they were not permitted to view or manage. The vulnerability could enable unauthorized translation, repository, and project-management operations beyond the user's intended permission scope. The issue has been resolved in Weblate version 2026.7, with a corresponding commit available on GitHub.