Junglewise Threat Intelligence

CVE-2026-49277: Rocket.Chat OAuth token persistence after account deactivation

CVE-2026-49277 · Severity: info · CVSS 2.3 · Published 2026-06-24

Technologies: Rocket.Chat. Vendors: Rocket.Chat.

Executive brief

Rocket.Chat is a customizable communications platform used for team collaboration. A security flaw allows deactivated users to maintain access to the platform if they have active OAuth tokens. This means an employee or user whose account was disabled by an administrator could still read messages or interact with the API, potentially leading to unauthorized data access or continued presence in private communications.

Technical details

A vulnerability in Rocket.Chat's OAuth implementation results in insufficient session expiration (CWE-613). When a user is deactivated via the `setUserActiveStatus` function, the system revokes Meteor login tokens but fails to invalidate OAuth access or refresh tokens. Furthermore, the OAuth bearer authentication and refresh-token handling logic do not verify the user's 'active' status before authorizing requests or issuing new tokens. An attacker with a previously established OAuth session can continue to access protected API endpoints and mint new access tokens even after their account has been administratively disabled. The issue is resolved in versions 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.

Affected products

  • RocketChat Rocket.Chat < 8.5.0, < 8.4.2, < 8.3.4, < 8.2.4, < 8.1.5, < 8.0.6, < 7.13.8, < 7.10.12

Timeline

  • 2026-05-25: advisory: Original GitHub security advisory published
  • 2026-06-24: disclosed: CVE published to NVD

References

Related threats