AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72719

MEDIUM · CVSS 6.7 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Authenticated account administrators in Chatwoot versions prior to 4.9.0 are vulnerable to a flaw that allows them to transfer critical resources, such as Portals and Automation Rules, to other accounts via the writable account_id parameter. This could lead to tenant isolation breaches, resulting in cross-account data exposure and unauthorized configuration changes. Organizations using Chatwoot should prioritize upgrading to version 4.9.0 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72719
Severity
MEDIUM
CVSS
6.7
EPSS
0.41%

Original NVD Description

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.