CyberRota Analysis
AI-GeneratedAuthenticated account administrators in Chatwoot versions prior to 4.9.0 are vulnerable to a flaw that allows them to transfer critical resources, such as Portals and Automation Rules, to other accounts via the writable account_id parameter. This could lead to tenant isolation breaches, resulting in cross-account data exposure and unauthorized configuration changes. Organizations using Chatwoot should prioritize upgrading to version 4.9.0 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.