Rocket.chat / Rocket.Chat
66 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-75575 | Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method | MEDIUM | 6.9 | Aug 25, 2026 |
| CVE-2026-65644 | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that a… | HIGH | 7.5 | Aug 21, 2026 |
| CVE-2026-65645 | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages… | MEDIUM | 4.3 | Aug 21, 2026 |
| CVE-2026-72919 | Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams | MEDIUM | 4.3 | Aug 10, 2026 |
| CVE-2026-72918 | Rocket.Chat: Insecure implementation of websocket notifications | MEDIUM | 5.4 | Aug 10, 2026 |
| CVE-2026-56845 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequ… | HIGH | 7.5 | Aug 4, 2026 |
| CVE-2026-58066 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validat… | CRITICAL | 9.8 | Jul 30, 2026 |
| CVE-2026-55762 | Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint | HIGH | 8.1 | Jun 24, 2026 |
| CVE-2026-55759 | Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay | HIGH | 7.4 | Jun 24, 2026 |
| CVE-2026-55666 | Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth | CRITICAL | 9.3 | Jun 24, 2026 |
| CVE-2026-49278 | Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation | MEDIUM | 6.7 | Jun 24, 2026 |
| CVE-2026-49277 | Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation | LOW | 2.3 | Jun 24, 2026 |
| CVE-2026-45757 | Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens | LOW | 2.3 | Jun 24, 2026 |
| CVE-2026-46423 | Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty | CRITICAL | 9.3 | Jun 24, 2026 |
| CVE-2026-45689 | Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO | CRITICAL | 9.1 | Jun 24, 2026 |
| CVE-2026-45688 | Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack | CRITICAL | 9.1 | Jun 24, 2026 |
| CVE-2026-45687 | Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage | HIGH | 8.5 | Jun 24, 2026 |
| CVE-2026-45677 | Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS | HIGH | 8.7 | Jun 24, 2026 |
| CVE-2026-47733 | Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images | MEDIUM | 4.4 | Jun 24, 2026 |
| CVE-2026-48616 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads… | CRITICAL | 9.3 | Jun 16, 2026 |
| CVE-2026-48929 | Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMes… | HIGH | 7.5 | Jun 16, 2026 |
| CVE-2026-32995 | The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-su… | HIGH | 7.5 | May 28, 2026 |
| CVE-2026-32994 | The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated… | MEDIUM | 5.3 | May 19, 2026 |
| CVE-2026-29197 | In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in… | MEDIUM | 4.3 | Apr 23, 2026 |
| CVE-2026-29198 | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the firs… | CRITICAL | 9.8 | Apr 22, 2026 |
Showing 1 to 25 of 66 CVEs