CVE-2026-72719 MEDIUM

CVE-2026-72719: Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter

Vendor Chatwoot
Product chatwoot
Weakness CWE-915
Published August 10, 2026
Last update August 10, 2026

CVSS base score

6.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.

Key dates

02Disclosure timeline

August 10, 2026 CVE published

Related vulnerabilities

04Related CVE