Rocketchat
12 CVEs tracked since 2026. Since Jun 2026, none of them reached CISA KEV.
Rocketchat CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-06 | 12 | 0 |
Products
The products that kept showing up in Rocketchat's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Rocketchat.
- CVE-2026-75575Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method5.3
- CVE-2026-65644Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized...7.5
- CVE-2026-65645Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped par...4.3
- CVE-2026-72919Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams4.3
- CVE-2026-72918Rocket.Chat: Insecure implementation of websocket notifications5.4
- CVE-2026-56845An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker...7.5
- CVE-2026-58066Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:...9.8
- CVE-2026-55762Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint8.1
- CVE-2026-55759Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay7.4
- CVE-2026-55666Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth—
- CVE-2026-49278Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation6.7
- CVE-2026-49277Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation—
- CVE-2026-45757Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens—
- CVE-2026-46423Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty—
- CVE-2026-45689Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO9.1
The record
- Peak rank
- #106 in Jun 2026
- Busiest month shown
- Jun 2026, 12 CVEs
- Months with a KEV entry
- 0 since Jun 2026
- Monthly snapshots
- 1 since 2026