{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/chatwoot--4.16.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-63765"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Chatwoot \u003c 4.16.0"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","web-application","vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["Chatwoot"],"content_html":"\u003cp\u003eA critical authentication bypass vulnerability, identified as CVE-2026-63765, has been discovered in Chatwoot versions prior to 4.16.0. This flaw resides within the application's direct uploads controller, a component responsible for managing file uploads to the ActiveStorage backend. Unauthenticated attackers can exploit this vulnerability by bypassing intended security checks to resolve any tenant account and conversation data without authorization. Subsequently, these attackers can obtain signed PUT URLs, typically reserved for authenticated users, which enable them to write arbitrary data as ActiveStorage blobs to the application's storage backend. This exposure allows for unauthorized data creation, modification, or deletion, posing a significant risk to data integrity and availability across affected Chatwoot instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a vulnerable Chatwoot instance running a version older than 4.16.0.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates a request to the application's direct uploads controller, bypassing the expected authentication mechanisms.\u003c/li\u003e\n\u003cli\u003eLeveraging the missing authentication checks (CWE-306) within the controller, the attacker successfully gains unauthorized access to internal application functions.\u003c/li\u003e\n\u003cli\u003eThe attacker exploits this bypass to resolve or retrieve sensitive information about any tenant account and conversation.\u003c/li\u003e\n\u003cli\u003eThrough the compromised controller, the attacker obtains signed PUT URLs, which are normally issued for legitimate, authenticated file upload operations.\u003c/li\u003e\n\u003cli\u003eUsing the acquired signed PUT URLs, the attacker sends PUT requests containing arbitrary data.\u003c/li\u003e\n\u003cli\u003eThis malicious data is then written as ActiveStorage blobs to the application's backend storage.\u003c/li\u003e\n\u003cli\u003eThe final objective is unauthorized data creation, modification, or corruption within targeted Chatwoot tenant accounts, impacting integrity and availability.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-63765 allows unauthenticated attackers to perform unauthorized data operations across any tenant account within a vulnerable Chatwoot instance. Attackers can create, modify, or potentially corrupt arbitrary ActiveStorage blobs by writing malicious data to the application's storage backend. While the NVD advisory does not specify observed victim counts or targeted sectors, the nature of the vulnerability could lead to widespread data integrity issues, service disruption, or reputational damage for any organization using affected Chatwoot versions, as sensitive customer conversation data could be manipulated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-63765 by upgrading all Chatwoot instances to version 4.16.0 or newer immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect CVE-2026-63765 Exploitation - Chatwoot Unauthenticated Direct Upload Access\u0026quot; to your SIEM and monitor for suspicious POST requests to the direct uploads controller.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive web server logging for HTTP methods, URI stems, and response statuses to capture activity related to the direct uploads controller.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T19:18:07Z","date_published":"2026-07-23T19:18:07Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63765-chatwoot-auth-bypass/","summary":"Chatwoot before version 4.16.0 contains an authentication bypass vulnerability in its direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account by exploiting missing authentication checks, leading to data manipulation.","title":"CVE-2026-63765: Chatwoot Authentication Bypass Vulnerability in Direct Uploads Controller","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63765-chatwoot-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Chatwoot \u003c 4.16.0","version":"https://jsonfeed.org/version/1.1"}