CVE-2026-72719
Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter
CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th
Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.
| CWE | CWE-915 |
| Vendor | chatwoot |
| Product | chatwoot |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for chatwoot chatwoot
Be the first to know when new medium vulnerabilities affecting chatwoot chatwoot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
Affected Versions
chatwoot / chatwoot
< 4.9.0
References
github.com: https://github.com/chatwoot/chatwoot/security/advisories/GHSA-x288-jh8j-348c github.com: https://github.com/chatwoot/chatwoot/pull/13116 github.com: https://github.com/chatwoot/chatwoot/commit/86da3f7c069f8ed6dce2576e1a760ca72b6f40fd github.com: https://github.com/chatwoot/chatwoot/releases/tag/v4.9.0