What is CVE-2026-72719?
This vulnerability affects Chatwoot versions prior to 4.9.0, where authenticated account administrators can exploit a writable account_id parameter to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts. This breaks tenant isolation and leads to cross-account data leakage. Affected systems should be immediately upgraded to version 4.9.0 or later.
Azərbaycanca: Bu boşluq Chatwoot müştəri cəlb etmə platformasında tapılıb və 4.9.0 versiyasından əvvəlki sistemlərə təsir edir. Autentifikasiya olunmuş hesab adminləri writable account_id parametri vasitəsilə Portalları, Avtomatlaşdırma Qaydalarını, Makrosları və Twilio Kanallarını digər hesablara köçürərək tenant izolyasiyasını poza bilər; bu da çarpaz hesab məlumat sızmasına səbəb olur. Təsirə məruz qalan sistemləri dərhal 4.9.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
Which platform is affected by CVE-2026-72719?
This vulnerability affects the Chatwoot customer engagement platform in versions prior to 4.9.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.