CVE-2026-63765 | Chatwoot up to 4.15.x Direct Uploads Controller missing authentication

SecurityVulns

A vulnerability was found in Chatwoot up to 4.15.x and classified as critical. Affected by this vulnerability is an unknown functionality of the component Direct Uploads Controller. Such manipulation leads to missing authentication.

This vulnerability is listed as CVE-2026-63765. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More