{"id":"CVE-2026-72719","title":"Chatwoot is a customer engagement suite","summary":"Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter…","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L","cwe":["CWE-915"],"published":"2026-08-10","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:55:04.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72719","references":[{"url":"https://github.com/chatwoot/chatwoot/commit/86da3f7c069f8ed6dce2576e1a760ca72b6f40fd","label":"security-advisories@github.com"},{"url":"https://github.com/chatwoot/chatwoot/pull/13116","label":"security-advisories@github.com"},{"url":"https://github.com/chatwoot/chatwoot/releases/tag/v4.9.0","label":"security-advisories@github.com"},{"url":"https://github.com/chatwoot/chatwoot/security/advisories/GHSA-x288-jh8j-348c","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.0041,"epssPercentile":0.34903,"ingestedAt":"2026-09-09T21:22:45.526Z","slug":"CVE-2026-72719","body":"## Overview\n\nChatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure, unauthorized configuration changes, or loss of access to transferred resources. This issue is fixed in version 4.9.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}