CVE Tools

Rocketchat

12 CVEs tracked since 2026. Since Jun 2026, none of them reached CISA KEV.

Rocketchat CVEs per month

Jun 2026 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Rocketchat CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-06120

Products

The products that kept showing up in Rocketchat's monthly top three, with their CVEs summed over those months.

  1. Rocket.chat121 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Rocketchat.

  1. CVE-2026-75575Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method5.3
  2. CVE-2026-65644Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized...7.5
  3. CVE-2026-65645Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped par...4.3
  4. CVE-2026-72919Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams4.3
  5. CVE-2026-72918Rocket.Chat: Insecure implementation of websocket notifications5.4
  6. CVE-2026-56845An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker...7.5
  7. CVE-2026-58066Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:...9.8
  8. CVE-2026-55762Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint8.1
  9. CVE-2026-55759Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay7.4
  10. CVE-2026-55666Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth—
  11. CVE-2026-49278Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation6.7
  12. CVE-2026-49277Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation—
  13. CVE-2026-45757Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens—
  14. CVE-2026-46423Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty—
  15. CVE-2026-45689Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO9.1

The record

Peak rank
#106 in Jun 2026
Busiest month shown
Jun 2026, 12 CVEs
Months with a KEV entry
0 since Jun 2026
Monthly snapshots
1 since 2026
Rocketchat's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store