Improper Authorization Vulnerability in Chatwoot by Chatwoot
CVE-2026-4990

6.9MEDIUM

Key Information:

Vendor

Chatwoot

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-4990?

A security weakness has been identified in Chatwoot versions up to 4.11.1, specifically within the Signup Endpoint function located at /app/login. This vulnerability allows an attacker to set the signupEnabled argument to true, resulting in improper authorization. By exploiting this flaw, remote attackers can manipulate the system's behavior, potentially leading to unauthorized access. The issue has been made public, yet the vendor has not addressed it despite prior notifications regarding the vulnerability.

Affected Version(s)

chatwoot 4.11.0

chatwoot 4.11.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabi_Ullah (VulDB User)
VulDB
.