Back to overview

CVE-2026-63765

HIGH
8.2
CVSS 3.1
Description
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend.

Metadata

CVE ID
CVE-2026-63765
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-18 12:34 UTC
Published
2026-07-23 17:52 UTC
Last updated
2026-07-23 17:52 UTC
Primary CWE
CWE-306
Missing Authentication for Critical Function
Vendor / Product
chatwoot / chatwoot
Sources
cve.org  ·  NVD

Severity & Metrics

8.2 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Affected products (1)
VendorProductPlatformVersions
chatwoot chatwoot 0 < 4.16.0
Weakness (CWE)
CWESourceDescription
CWE-306 cna Missing Authentication for Critical Function
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.8 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
8.2 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Back to overview