PT-2026-64147 · Chatwoot · Chatwoot
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Chatwoot versions prior to 4.16.0
Description
An authentication bypass exists in the direct uploads controller. This flaw allows unauthenticated attackers to resolve any account and conversation to create arbitrary ActiveStorage blobs within any tenant account. By exploiting the missing authentication checks, attackers can obtain signed PUT URLs to write arbitrary data directly to the application storage backend.
Recommendations
Update to version 4.16.0 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chatwoot