CVE-2026-63765
Last modified
CVE-2026-63765 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| chatwoot | chatwoot | < 4.16.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-63765?
How severe is CVE-2026-63765?
How do I fix CVE-2026-63765?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6376A weakness in SpiceJet’s public booking retrieval page permi…8.7
- CVE-2026-63760SurrealDB before 3.1.0 fails to enforce the configured recur…8.7
- CVE-2026-63761SurrealDB before 3.1.0 silently substitutes the ES384 algori…5.3
- CVE-2026-63762SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains …6.5
- CVE-2026-63763SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a co…8.8
- CVE-2026-63764LMDeploy through 0.14.0, fixed in commit 03c3130, contains a…8.6
- CVE-2026-63766GPT-SoVITS through 20250606v2pro contains an OS command inje…9.8
- CVE-2026-63767ktransformers through 0.6.3, fixed in commit def0f93, contai…9.8
- CVE-2026-63768cal.diy through 6.2.0 contains an open redirect vulnerabilit…5.3
- CVE-2026-63769Huginn through 2022.08.18 contains a server-side request for…7.7
- CVE-2026-63770Glance through 0.8.5 contains an IP address spoofing vulnera…8.2
- CVE-2026-63771Adminer before 5.4.3 contains a cookie injection vulnerabili…7.1
Are you affected by CVE-2026-63765?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
