CVE-2026-44707
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker could pre-register an email address they did not own and set a password. If the legitimate owner of that email later signed in to Chatwoot using Google OAuth (or another OmniAuth provider), the OAuth flow silently confirmed the existing account without invalidating the attacker's pre-set credentials.
Leer descripción completaMostrar menos
The attacker could then continue to log in with the password they had originally chosen and access any data the victim subsequently entered into the dashboard, including PII, API keys, and other sensitive information. This vulnerability is fixed in 4.13.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.46%
- Percentil entre todas las CVEs puntuadas: 37
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-283, CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-44707",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-44707",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-27T17:22:42.396721Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "chatwoot",
"product": "chatwoot",
"versions": [
{
"status": "affected",
"version": ">= 2.14.0, < 4.13.0"
}
]
}
]
}
],
"published": "2026-05-26T18:16:50.743",
"references": [
{
"url": "https://github.com/chatwoot/chatwoot/commit/211fb1102dd208daee414cff1b8d71ea27ac5ebf",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/chatwoot/chatwoot/pull/13878",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/chatwoot/chatwoot/security/advisories/GHSA-8qxm-4p4p-cfhm",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-283"
},
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker could pre-register an email address they did not own and set a password. If the legitimate owner of that email later signed in to Chatwoot using Google OAuth (or another OmniAuth provider), the OAuth flow silently confirmed the existing account without invalidating the attacker's pre-set credentials. The attacker could then continue to log in with the password they had originally chosen and access any data the victim subsequently entered into the dashboard, including PII, API keys, and other sensitive information. This vulnerability is fixed in 4.13.0."
},
{
"lang": "es",
"value": "Chatwoot es una suite de interacción con el cliente. Desde la versión 2.14.0 hasta antes de la 4.13.0, existía una vulnerabilidad de Pre-Account Takeover (Pre-ATO) en el flujo de autenticación de Chatwoot. Debido a que la confirmación de correo electrónico no se aplicaba antes de que una cuenta fuera utilizable, un atacante podía pre-registrar una dirección de correo electrónico que no poseía y establecer una contraseña. Si el propietario legítimo de ese correo electrónico iniciaba sesión más tarde en Chatwoot usando Google OAuth (o cualquier otro proveedor de OmniAuth), el flujo de OAuth confirmaba silenciosamente la cuenta existente sin invalidar las credenciales preestablecidas del atacante. El atacante podía entonces continuar iniciando sesión con la contraseña que había elegido originalmente y acceder a cualquier dato que la víctima introdujera posteriormente en el panel de control, incluyendo PII, claves de API y otra información sensible. Esta vulnerabilidad está corregida en la versión 4.13.0."
}
],
"lastModified": "2026-07-24T11:10:00.170",
"sourceIdentifier": "security-advisories@github.com"
}