What is CVE-2026-63765?
Versions of Chatwoot prior to 4.16.0 contain an authentication bypass vulnerability in the direct upload controller. This flaw allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account.
Azərbaycanca: Chatwoot platformasının 4.16.0 versiyasından əvvəlki versiyalarında birbaşa yükləmə (direct upload) mexanizmində autentifikasiya zəifliyi mövcuddur. Bu boşluq autentifikasiya olunmamış hücumçulara istənilən təşkilat hesabında ixtiyari fayllar yükləməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Does an attacker need to have an account to exploit CVE-2026-63765?
No, this vulnerability allows unauthenticated attackers to carry out the attack.
Which versions of Chatwoot are affected by CVE-2026-63765?
Versions of Chatwoot prior to 4.16.0 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.