CVE-2026-4990: chatwoot Signup Endpoint login improper authorization
A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argument signupEnabled with the input true leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4990?
CVE-2026-4990 is classified as a critical severity vulnerability due to improper authorization in the Signup Endpoint.
How do I fix CVE-2026-4990?
To fix CVE-2026-4990, upgrade Chatwoot to version 4.11.2 or later, which addresses the improper authorization issue.
What does CVE-2026-4990 affect?
CVE-2026-4990 affects the Signup Endpoint functionality in Chatwoot up to version 4.11.1.
What kind of attack can CVE-2026-4990 facilitate?
CVE-2026-4990 can enable unauthorized access or account creation through manipulation of the signupEnabled parameter.
Is authentication required to exploit CVE-2026-4990?
No, CVE-2026-4990 can be exploited without authentication, making it particularly dangerous.