CVE-2026-4990 | chatwoot up to 4.11.1 Signup Endpoint /app/login signupEnabled improper authorization
A vulnerability described as critical has been identified in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argument signupEnabled with the input true leads to improper authorization.
This vulnerability is documented as CVE-2026-4990. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.