Authentication Bypass in Chatwoot by Chatwoot Inc.
CVE-2026-63765
Key Information:
Badges
What is CVE-2026-63765?
Chatwoot, prior to version 4.16.0, is susceptible to an authentication bypass in the direct uploads controller. This flaw allows attackers without authorization to create arbitrary ActiveStorage blobs within any tenant account. By exploiting the absence of proper authentication checks, attackers can identify all accounts and conversations, gaining access to signed PUT URLs that permit the upload of arbitrary data to the application's storage backend. This vulnerability represents a significant risk, as it can lead to unauthorized data manipulation and exposure.
Affected Version(s)
chatwoot 0 < 4.16.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
