CVE-2026-63765

Source
https://cve.org/CVERecord?id=CVE-2026-63765
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63765.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63765
Published
2026-07-23T17:52:10Z
Modified
2026-08-12T03:51:35Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
Details

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63765.json"
}
References

Affected packages

Git / github.com/chatwoot/chatwoot

Affected ranges

Type
GIT
Repo
https://github.com/chatwoot/chatwoot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.16.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.2.4
1.4.2
2.*
2.16.1
4.*
4.11.2
v0.*
v0.1.0
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.11.0
v1.11.1
v1.12.0
v1.12.1
v1.12.2
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.15.0
v1.15.1
v1.16.1
v1.16.2
v1.17.0
v1.17.1
v1.18.0
v1.18.1
v1.19.0
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.20.0
v1.21.0
v1.21.1
v1.22.0
v1.22.1
v1.3.0
v1.4.0
v1.4.1
v1.4.2
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.9.0
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.12.0
v2.12.1
v2.13.0
v2.13.1
v2.14.0
v2.15.0
v2.16.0
v2.17.0
v2.17.1
v2.18.0
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.3.2
v2.4.0
v2.4.1
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.*
v3.0.0
v3.0.0-rc1
v3.1.0
v3.1.1
v3.10.0
v3.10.1
v3.10.2
v3.11.0
v3.11.1
v3.12.0
v3.13.0
v3.14.0
v3.14.1
v3.15.0
v3.16.0
v3.2.0
v3.3.0
v3.3.1
v3.4.0
v3.5.0
v3.5.1
v3.5.2
v3.6.0
v3.7.0
v3.8.0
v3.9.0
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.1.0
v4.10.0
v4.10.1
v4.11.0
v4.11.1
v4.11.2
v4.12.0
v4.12.1
v4.13.0
v4.14.0
v4.14.1
v4.14.2
v4.15.0
v4.15.1
v4.2.0
v4.3.0
v4.4.0
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.7.0
v4.8.0
v4.9.0
v4.9.1
v4.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63765.json"