Improper Authorization Vulnerability in Chatwoot by Chatwoot
CVE-2026-4990
6.9MEDIUM
What is CVE-2026-4990?
A security weakness has been identified in Chatwoot versions up to 4.11.1, specifically within the Signup Endpoint function located at /app/login. This vulnerability allows an attacker to set the signupEnabled argument to true, resulting in improper authorization. By exploiting this flaw, remote attackers can manipulate the system's behavior, potentially leading to unauthorized access. The issue has been made public, yet the vendor has not addressed it despite prior notifications regarding the vulnerability.
Affected Version(s)
chatwoot 4.11.0
chatwoot 4.11.1
