CVE-2026-44707 Details
Description
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker could pre-register an email address they did not own and set a password. If the legitimate owner of that email later signed in to Chatwoot using Google OAuth (or another OmniAuth provider), the OAuth flow silently confirmed the existing account without invalidating the attacker's pre-set credentials. The attacker could then continue to log in with the password they had originally chosen and access any data the victim subsequently entered into the dashboard, including PII, API keys, and other sensitive information. This vulnerability is fixed in 4.13.0.
A Pre-Account Takeover vulnerability has been identified in Chatwoot's authentication process, affecting versions 2.14.0 prior to 4.13.0. The issue arises because email confirmation was not required before an account could be used. This allowed an attacker to register an email address they did not own, set a password, and wait for the legitimate owner to sign in using Google OAuth or another OmniAuth provider. The OAuth process would silently confirm the account without invalidating the attacker's password, enabling access to sensitive data on the dashboard, such as personal information and API keys.
Users are advised to upgrade to Chatwoot version 4.13.0 or later. If an immediate upgrade is not possible, OAuth sign-in providers can be disabled temporarily, and user accounts should be audited for unconfirmed entries created via email/password sign-up before the first OAuth login.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 26, 2026CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/chatwoot/chatwoot/commit/211fb1102dd208daee414cff1b8d71ea27ac5ebf | [email protected] | Source CodeVendor |
| https://github.com/chatwoot/chatwoot/pull/13878 | [email protected] | Issue TrackingVendor |
| https://github.com/chatwoot/chatwoot/security/advisories/GHSA-8qxm-4p4p-cfhm | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-283 | Unverified Ownership | [email protected] |
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Chatwoot | >= 2.14.0, < 4.13.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |
Volerion