CVE-2026-44707
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker could pre-register an email address they did not own and set a password. If the legitimate owner of that email later signed in to Chatwoot using Google OAuth (or another OmniAuth provider), the OAuth flow silently confirmed the existing account without invalidating the attacker's pre-set credentials.
Read full descriptionShow less
The attacker could then continue to log in with the password they had originally chosen and access any data the victim subsequently entered into the dashboard, including PII, API keys, and other sensitive information. This vulnerability is fixed in 4.13.0.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Base score: 6.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.46%
- Percentile among all scored CVEs: 37
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-283, CWE-287
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-44707",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-44707",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-27T17:22:42.396721Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "chatwoot",
"product": "chatwoot",
"versions": [
{
"status": "affected",
"version": ">= 2.14.0, < 4.13.0"
}
]
}
]
}
],
"published": "2026-05-26T18:16:50.743",
"references": [
{
"url": "https://github.com/chatwoot/chatwoot/commit/211fb1102dd208daee414cff1b8d71ea27ac5ebf",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/chatwoot/chatwoot/pull/13878",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/chatwoot/chatwoot/security/advisories/GHSA-8qxm-4p4p-cfhm",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-283"
},
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker could pre-register an email address they did not own and set a password. If the legitimate owner of that email later signed in to Chatwoot using Google OAuth (or another OmniAuth provider), the OAuth flow silently confirmed the existing account without invalidating the attacker's pre-set credentials. The attacker could then continue to log in with the password they had originally chosen and access any data the victim subsequently entered into the dashboard, including PII, API keys, and other sensitive information. This vulnerability is fixed in 4.13.0."
},
{
"lang": "es",
"value": "Chatwoot es una suite de interacción con el cliente. Desde la versión 2.14.0 hasta antes de la 4.13.0, existía una vulnerabilidad de Pre-Account Takeover (Pre-ATO) en el flujo de autenticación de Chatwoot. Debido a que la confirmación de correo electrónico no se aplicaba antes de que una cuenta fuera utilizable, un atacante podía pre-registrar una dirección de correo electrónico que no poseía y establecer una contraseña. Si el propietario legítimo de ese correo electrónico iniciaba sesión más tarde en Chatwoot usando Google OAuth (o cualquier otro proveedor de OmniAuth), el flujo de OAuth confirmaba silenciosamente la cuenta existente sin invalidar las credenciales preestablecidas del atacante. El atacante podía entonces continuar iniciando sesión con la contraseña que había elegido originalmente y acceder a cualquier dato que la víctima introdujera posteriormente en el panel de control, incluyendo PII, claves de API y otra información sensible. Esta vulnerabilidad está corregida en la versión 4.13.0."
}
],
"lastModified": "2026-07-24T11:10:00.170",
"sourceIdentifier": "security-advisories@github.com"
}