CVE-2026-63765

HIGH

Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation

Title source: cna
STIX 2.1

Description

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend.

References (5)

Core 5
Core References
Exploit technical-description exploit issue-tracking
Researcher Disclosure
https://github.com/chatwoot/chatwoot/issues/15072
Release Notes release-notes patch
Release Notes
https://github.com/chatwoot/chatwoot/releases/tag/v4.16.0
Issue Tracking issue-tracking patch
Pull Request
https://github.com/chatwoot/chatwoot/pull/15039

Scores

CVSS v3 8.2
EPSS 0.0038
EPSS Percentile 30.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
chatwoot/chatwoot < 4.16.0
Published Jul 23, 2026
Tracked Since Jul 24, 2026