CVE-2026-49278
- EPSS 0.24%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 25.06.2026 14:19:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-information-by...
CVE-2026-49277
- EPSS 0.22%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 25.06.2026 14:19:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth bearer or refresh tokens when a user is deactivated. A deacti...
CVE-2026-47733
- EPSS 0.12%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 25.06.2026 16:16:35
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled src values directly into <a href> and <img src> attributes without protocol sa...
CVE-2026-46423
- EPSS 0.15%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 25.06.2026 14:19:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML service provider implementation silently skips both SAML Response and Assert...
CVE-2026-45757
- EPSS 0.22%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 25.06.2026 16:16:35
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through users.deactivateIdle to keep using already-issued ...
CVE-2026-45689
- EPSS 0.31%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 25.06.2026 14:19:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbit...
CVE-2026-45677
- EPSS 0.45%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 25.06.2026 14:19:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML integration does not verify the signature on inbound LogoutRequest messages....
CVE-2026-45687
- EPSS 0.21%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 25.06.2026 14:19:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMessage DDP method passes the entire attacker-supplied file object into U...
CVE-2026-45688
- EPSS 0.29%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 25.06.2026 14:19:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login handler forwards the client-supplied options.cas.credentialToken value ...
CVE-2026-55762
- EPSS 0.32%
- Veröffentlicht 24.06.2026 21:08:01
- Zuletzt bearbeitet 25.06.2026 14:19:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint REST endpoint enforces authentication (authRequired: true) but performs no...