Executive brief
Rocket.Chat, a popular communication platform, contains a critical security flaw in its Single Sign-On (SSO) system. An attacker can bypass authentication to log in as any user, including administrators, without needing a password. This could lead to a total compromise of the platform, allowing unauthorized access to private messages, sensitive company data, and administrative controls.
Technical details
A vulnerability exists in Rocket.Chat's SAML SSO implementation (CWE-287) where XML signatures are verified but not correctly bound to the samlp:Response or saml:Assertion elements. This flaw allows for a 'SAML wrapping' style attack. A remote, unauthenticated attacker can submit a specially crafted XML document containing forged identity attributes alongside a valid signature from a trusted Identity Provider (IdP). Because the application validates the signature but fails to ensure it covers the specific identity claims being processed, the attacker can impersonate any user. The issue is resolved in versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14.
Affected products
- Rocket.Chat Rocket.Chat < 8.7.0, < 8.6.1, < 8.5.2, < 8.4.5, < 8.3.7, < 8.2.7, < 8.1.7, < 8.0.8, < 7.10.14
Timeline
- 2026-07-08: patched: Fix merged into Rocket.Chat develop branch
- 2026-07-30: advisory: CVE published via NVD and HackerOne