PT-2026-43349 · Chatwoot · Chatwoot

Dishantchavda

·

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-44707

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chatwoot versions 2.14.0 through 4.12.x
Description A Pre-Account Takeover (Pre-ATO) issue exists in the authentication flow. Because email confirmation is not enforced before an account becomes usable, an attacker can pre-register an email address they do not own and set a password. If the legitimate owner of that email later signs in using Google OAuth or another OmniAuth provider, the OAuth flow silently confirms the existing account without invalidating the attacker's pre-set credentials. This allows the attacker to log in with their chosen password and access sensitive data entered by the victim, such as personally identifiable information (PII) and API keys.
Recommendations Update to version 4.13.0.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44707

Affected Products

Chatwoot