{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3achatwootchatwoot/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-44706"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Chatwoot (\u003c= 4.11.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Chatwoot"],"content_html":"\u003cp\u003eChatwoot versions 4.11.1 and earlier contain a critical SQL injection vulnerability in the FilterService, identified as CVE-2026-44706. The vulnerability resides in the \u003ccode\u003eFilterService#lt_gt_filter_values\u003c/code\u003e method, which fails to properly parameterize values within the \u003ccode\u003eis_greater_than\u003c/code\u003e operator used during conversation filtering. An authenticated attacker, such as a malicious or compromised agent, can send specially crafted requests to the \u003ccode\u003e/api/v1/accounts/{account_id}/conversations/filter\u003c/code\u003e endpoint to execute arbitrary SQL commands against the underlying PostgreSQL database. This allows for the exfiltration of sensitive information, including user credentials and API tokens. The availability of public proof-of-concept exploit code increases the risk of successful exploitation in enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid authentication credentials for a low-privileged agent account in the target Chatwoot instance.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the \u003ccode\u003e/api/v1/accounts/{account_id}/conversations/filter\u003c/code\u003e API endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious SQL payloads into the request body, specifically targeting the \u003ccode\u003eis_greater_than\u003c/code\u003e operator parameters.\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003eFilterService\u003c/code\u003e component processes the unparameterized input, executing the malicious SQL query on the PostgreSQL database.\u003c/li\u003e\n\u003cli\u003eAttacker employs boolean-based or time-based blind SQL injection techniques to infer database structure and content.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates sensitive rows, specifically targeting user account tables, credentials, and API tokens.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved: unauthorized access to administrative credentials and internal platform data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated agent to bypass standard authorization controls and dump the entire PostgreSQL database. This results in the exposure of highly sensitive data, including customer PII, internal communication logs, and administrative API tokens, which could be leveraged for lateral movement or full platform takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Chatwoot instances to a version later than 4.11.1 immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict monitoring on the \u003ccode\u003e/api/v1/accounts/{account_id}/conversations/filter\u003c/code\u003e endpoint for anomalous HTTP request bodies containing SQL syntax characters (e.g., \u003ccode\u003e'\u003c/code\u003e, \u003ccode\u003e--\u003c/code\u003e, \u003ccode\u003eUNION\u003c/code\u003e, \u003ccode\u003eSELECT\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eReview access logs for excessive or unusual activity originating from low-privileged agent accounts.\u003c/li\u003e\n\u003cli\u003ePerform a security audit of current agent permissions to ensure the principle of least privilege is enforced within the Chatwoot dashboard.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T06:12:51Z","date_published":"2026-09-14T06:12:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-chatwoot-sqli/","summary":"An authenticated SQL injection vulnerability (CVE-2026-44706) in Chatwoot versions 4.11.1 and earlier allows attackers to perform unauthorized database queries and exfiltrate sensitive data.","title":"SQL Injection in Chatwoot FilterService","url":"https://feed.craftedsignal.io/briefs/2026-09-chatwoot-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}