SQL injection in Chatwoot - CVE-2026-44706
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the conversation and contact filter APIs when processing filter requests that use custom attributes. A remote user can send a specially crafted filter payload to disclose sensitive information.
If no date or number custom attribute exists, one can be created through the custom attribute definitions endpoint, making the precondition trivial to satisfy.