CVE-2026-63765
HIGHChatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
Title source: cnaDescription
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend.
References (5)
Core 5
Core References
Exploit technical-description
exploit
issue-tracking
Researcher Disclosure
https://github.com/chatwoot/chatwoot/issues/15072
Release Notes release-notes
patch
Release Notes
https://github.com/chatwoot/chatwoot/releases/tag/v4.16.0
Patch patch
Patch Commit
https://github.com/chatwoot/chatwoot/commit/8dd0d08322edafaec24624b72ed2f6045921cb7b
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/chatwoot-unauthenticated-activestorage-direct-upload-arbitrary-blob-creation
Scores
CVSS v3
8.2
EPSS
0.0038
EPSS Percentile
30.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (1)
chatwoot/chatwoot
< 4.16.0
Published
Jul 23, 2026
Tracked Since
Jul 24, 2026