CVE-2026-44706 is a SQL injection vulnerability in Chatwoot affecting versions 2.2.0 through before 4.11.2. The flaw exists in the conversation and contact filter APIs when filtering on custom attributes of type date or number using the is_greater_than or is_less_than operators. In this code path, user-controlled input from the values field of the filter payload is interpolated directly into backend SQL queries without proper parameterization, enabling SQL injection. The issue affects the /api/v1/accounts/{account_id}/conversations/filter and /api/v1/accounts/{account_id}/contacts/filter endpoints; the provided context also lists /api/v1/accounts/{account_id}/custom_attribute_definitions as affected. Exploitation is described as time-based blind SQL injection by an authenticated user with account access, allowing arbitrary SQL execution against the application's database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused proof-of-concept exploit for an authenticated SQL injection in Chatwoot FilterService, identified as CVE-2026-44706 and affecting Chatwoot <= 4.11.1. The repo contains three files: a README describing the vulnerability and usage, a docker-compose.yml that provisions a local vulnerable Chatwoot/PostgreSQL/Redis lab, and the main exploit script at exploit/poc.py. The Python PoC is the operational core. It authenticates to /api/v1/profile using a supplied api_access_token, then sends crafted JSON filter payloads to /api/v1/accounts/{account_id}/conversations/filter. The injection is placed inside the created_at filter value for the is_greater_than operator, matching the vulnerable code path described in the README. The exploit supports four modes: check (boolean-style confirmation using OR TRUE), timebased (pg_sleep timing confirmation), extract (blind extraction of arbitrary SQL query results), and creds (enumeration of users plus extraction of email addresses, bcrypt password hashes, and user access tokens from users and access_tokens tables). Extraction is implemented through repeated time-based blind predicates and character-by-character inference. The exploit is not just a detector: it provides practical post-exploitation data access against the backend database. It does not deliver OS-level code execution or a shell; instead, its payload is SQL focused on database disclosure and denial-of-service via sleep-based queries. The docker-compose file indicates the intended test setup and confirms PostgreSQL dependency, which aligns with the exploit's use of pg_sleep and PostgreSQL casting syntax. Overall, this is a genuine, standalone authenticated web exploit PoC with credential-dumping capability.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.