๐Ÿ” CVE Alert

CVE-2026-72719

MEDIUM 6.7

Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter

CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.

CWE CWE-915
Vendor chatwoot
Product chatwoot
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for chatwoot chatwoot

Be the first to know when new medium vulnerabilities affecting chatwoot chatwoot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

chatwoot / chatwoot
< 4.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/chatwoot/chatwoot/security/advisories/GHSA-x288-jh8j-348c github.com: https://github.com/chatwoot/chatwoot/pull/13116 github.com: https://github.com/chatwoot/chatwoot/commit/86da3f7c069f8ed6dce2576e1a760ca72b6f40fd github.com: https://github.com/chatwoot/chatwoot/releases/tag/v4.9.0