CVE-2026-72719: Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter
Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable accountid parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Chatwootto a version that resolves this vulnerability.Fixed in 4.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72719?
The severity of CVE-2026-72719 is medium with a score of 6.7.
What does CVE-2026-72719 affect?
CVE-2026-72719 affects the Chatwoot customer engagement suite, specifically allowing cross-account resource transfers.
How do I fix CVE-2026-72719?
To fix CVE-2026-72719, update Chatwoot to version 4.9.0 or later to mitigate the vulnerability.
What is the risk associated with CVE-2026-72719?
CVE-2026-72719 has a risk score of 57, indicating moderate potential impact on data isolation.
Who is affected by CVE-2026-72719?
Authenticated account administrators of Chatwoot could be affected by CVE-2026-72719 due to the ability to transfer resources between accounts.