Impact
Chatwoot customers were able to transfer Portals, Automation Rules, Macros, and Twilio Channels from one account to another by modifying the writable account_id parameter. This flaw allowed an authenticated account administrator to move resources between accounts, breaking tenant isolation and exposing sensitive information or altering critical configurations. The underlying weakness is an improper validation of identifier values (CWE‑915), and the result could include cross‑account data disclosure, unauthorized changes, or loss of access to transferred resources.
Affected Systems
The affected product is Chatwoot, vendor chatwoot:chatwoot, and all releases prior to version 4.9.0 are vulnerable. The fix is included in release 4.9.0.
Risk and Exploitability
The CVSS score of 6.7 marks this as a medium‑severity vulnerability. EPSS data are not available, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitability appears to require an authenticated account administrator who can invoke the transfer API, which suggests a local‑administrator or privileged user attack vector. If such a role exists, the risk is that that user can transfer and expose resources across accounts.
OpenCVE Enrichment