CVE-2026-78380
- EPSS 0.28%
- Veröffentlicht 24.08.2026 13:26:56
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual post is marked private but does n...
CVE-2026-65645
- EPSS -
- Veröffentlicht 21.08.2026 02:53:43
- Zuletzt bearbeitet 04.09.2026 18:27:21
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator...
CVE-2026-65644
- EPSS -
- Veröffentlicht 21.08.2026 02:53:43
- Zuletzt bearbeitet 04.09.2026 18:30:22
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is store...
CVE-2026-56845
- EPSS 0.4%
- Veröffentlicht 04.08.2026 00:43:48
- Zuletzt bearbeitet 09.09.2026 15:41:24
An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.
CVE-2026-58066
- EPSS 0.24%
- Veröffentlicht 30.07.2026 06:25:55
- Zuletzt bearbeitet 25.08.2026 18:12:04
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped documen...
- EPSS 0.72%
- Veröffentlicht 16.06.2026 23:08:37
- Zuletzt bearbeitet 16.06.2026 23:08:37
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMessage Meteor method permanently deletes any uploaded file by ID without requiring authentica...
- EPSS 0.33%
- Veröffentlicht 16.06.2026 23:08:37
- Zuletzt bearbeitet 16.06.2026 23:08:37
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+r...
CVE-2026-32995
- EPSS 0.28%
- Veröffentlicht 28.05.2026 04:01:37
- Zuletzt bearbeitet 01.06.2026 18:04:45
The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor...
CVE-2026-32994
- EPSS 0.25%
- Veröffentlicht 19.05.2026 04:43:41
- Zuletzt bearbeitet 24.07.2026 12:10:00
The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct mess...
CVE-2026-29197
- EPSS 0.18%
- Veröffentlicht 23.04.2026 23:19:40
- Zuletzt bearbeitet 28.04.2026 19:34:33
In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing authenticated users without the proper permissions...