---
cve: "CVE-2026-72719"
severity: "MEDIUM"
cvss: 6.7
epss: "41%"
vendor: "chatwoot"
kev: false
exploited: false
published: "2026-08-10 16:19:49"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T01:48:22+02:00"
---

# CVE-2026-72719

> 6.7 MEDIUM · 🧪 PoC

## Beschreibung

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- 86da3f7c069f8ed6dce2576e1a760ca72b6f40fd (Commit)
- 73140998ff2a9d514d34d259a6bd0f15b33c3804 (Commit)

## Referenzen

- <https://github.com/chatwoot/chatwoot/security/advisories/GHSA-x288-jh8j-348c>
- <https://github.com/chatwoot/chatwoot/pull/13116>
- <https://github.com/chatwoot/chatwoot/commit/86da3f7c069f8ed6dce2576e1a760ca72b6f40fd>
- <https://github.com/chatwoot/chatwoot/releases/tag/v4.9.0>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-72719) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
