SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-63765

HIGH · CVSS 8.2 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

Chatwoot versions prior to 4.16.0 are vulnerable to an authentication bypass in the direct uploads controller, enabling unauthenticated attackers to create arbitrary ActiveStorage blobs across any tenant account. This vulnerability allows attackers to exploit missing authentication checks to access any account and conversation, potentially leading to unauthorized data manipulation in the application's storage backend. Organizations using Chatwoot should prioritize patching this vulnerability to safeguard against unauthorized data access and integrity issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63765
Severity
HIGH
CVSS
8.2
EPSS
0.38%

Original NVD Description

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend.