PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63765 chatwoot CVE debrief

CVE-2026-63765 is an authentication bypass vulnerability in Chatwoot before 4.16.0. The vulnerability exists in the direct uploads controller, allowing unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. This is achieved by exploiting missing authentication checks, which enable attackers to resolve any account and conversation. Subsequently, attackers can obtain signed PUT URLs to write arbitrary data to the application's storage backend.

Vendor
chatwoot
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-23
Original CVE updated
2026-07-27
Advisory published
2026-07-23
Advisory updated
2026-07-27

Who should care

Users of Chatwoot versions prior to 4.16.0 should be aware of this vulnerability and take immediate action to upgrade to the patched version. Additionally, administrators and security teams responsible for maintaining and securing Chatwoot installations should prioritize patching and monitoring for potential exploitation attempts.

Technical summary

The CVE-2026-63765 vulnerability is caused by a lack of authentication checks in the direct uploads controller of Chatwoot before version 4.16.0. This oversight allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. By resolving any account and conversation, attackers can obtain signed PUT URLs, enabling them to write arbitrary data to the application's storage backend. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity.

Defensive priority

High

Recommended defensive actions

  • Upgrade Chatwoot to version 4.16.0 or later
  • Review and monitor direct uploads controller for suspicious activity
  • Implement additional authentication checks for storage backend access
  • Conduct regular security audits and vulnerability assessments
  • Confirm whether affected Chatwoot deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed Chatwoot systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated Chatwoot assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-07-23T19:17:03.560Z and was last modified on 2026-07-27T17:16:39.083Z. The NVD entry is currently Deferred. Multiple source references are provided, including GitHub commits, issues, and releases, as well as a Vulncheck advisory.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T19:17:03.560Z and has not been modified since then. The NVD entry is currently Deferred.