rocket-chat
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting rocket-chat.
- CVE-2026-75575Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method5.3
- CVE-2026-65644Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized...7.5
- CVE-2026-65645Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped par...4.3
- CVE-2026-72919Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams4.3
- CVE-2026-72918Rocket.Chat: Insecure implementation of websocket notifications5.4
- CVE-2026-56845An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker...7.5
- CVE-2026-58066Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:...9.8
- CVE-2026-55762Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint8.1
- CVE-2026-55759Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay7.4
- CVE-2026-55666Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth
- CVE-2026-49278Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation6.7
- CVE-2026-49277Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation
- CVE-2026-45757Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens
- CVE-2026-46423Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty
- CVE-2026-45689Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO9.1