Executive brief
Rocket.Chat is a communications platform used for team collaboration and messaging. A security flaw allows users who have been deactivated by an administrator for inactivity to continue accessing the system using their existing login tokens. This means a deactivated user could still read or send messages via the API, potentially bypassing administrative controls intended to restrict access.
Technical details
A session-revocation vulnerability exists in Rocket.Chat's 'users.deactivateIdle' functionality. While the standard deactivation path correctly calls 'Users.unsetLoginTokens', the idle deactivation route only updates the user's active status and 'inactiveReason' without clearing 'services.resume.loginTokens'. Because the REST API authentication logic validates the hashed token without verifying if the 'active' flag is set to true, deactivated users can continue to interact with authenticated endpoints. This issue is resolved in versions 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.
Affected products
- RocketChat Rocket.Chat < 8.5.0, < 8.4.2, < 8.3.4, < 8.2.4, < 8.1.5, < 8.0.6, < 7.13.8, < 7.10.12
Timeline
- 2026-05-25: advisory: GitHub Security Advisory published
- 2026-06-24: disclosed: CVE published to NVD