Junglewise Threat Intelligence

CVE-2026-55666: Rocket.Chat account takeover via Apple OAuth login handler

CVE-2026-55666 · Severity: info · CVSS 9.3 · Published 2026-06-24

Technologies: RocketChat Rocket.Chat. Vendors: Rocket.Chat.

Executive brief

Rocket.Chat is an open-source communications platform used for team collaboration and messaging. A security flaw in the Apple login process allows attackers to bypass authentication and take over user accounts. By providing a specially crafted login request, an attacker can impersonate any user on the platform without knowing their password, potentially leading to full access to private conversations and sensitive corporate data.

Technical details

An authentication bypass vulnerability exists in Rocket.Chat's Apple OAuth implementation within 'loginHandler.ts'. The 'handleIdentityToken' function parses a JWT issued by Apple; however, if the JWT does not contain an email address, the application incorrectly falls back to an unverified email value provided directly in the login request. An attacker can exploit this by forging an Apple JWT that lacks an email claim and supplying the target victim's email address in the request body. This allows the attacker to successfully authenticate as the target user. The vulnerability is patched in versions 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13.

Affected products

  • RocketChat Rocket.Chat < 7.10.13, 8.0.0-rc.0 - 8.0.6, 8.1.0-rc.0 - 8.1.5, 8.2.0-rc.0 - 8.2.5, 8.3.0-rc.0 - 8.3.5, 8.4.0-rc.0 - 8.4.3, 8.5.0-rc.0 - 8.5.0

Timeline

  • 2026-06-16: advisory: GitHub advisory published by Rocket.Chat
  • 2026-06-24: disclosed: CVE published to NVD

References

Related threats