Vendor
Rocket.chat vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 25 vulnerabilities in Rocket.chat: 0 in the last 7 days and 4 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-75575, was published on 25 August 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 4
- Critical, all time
- 5
- Exploited in the wild
- 0
About Rocket.chat
An open-source communication software company specializing in team collaboration and customer service solutions.
Rocket.chat technologies
Latest Rocket.chat vulnerabilities
- CVE-2026-75575: Rocket.Chat sendForgotPasswordEmail method missing DDP rate limitmediumCVSS 5.3EPSS 0.4%
- CVE-2026-65645: Rocket.Chat Meteor DDP method authorization bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2026-65644: Rocket.Chat Omnichannel queue stored XSS via visitor namehighCVSS 7.5EPSS 0.5%
- CVE-2026-58066: Rocket.Chat authentication bypass in SAML SSOcriticalCVSS 9.8
- CVE-2026-55762: Rocket.Chat missing authorization in fingerprint REST endpointhighCVSS 8.1
- CVE-2026-55759: Rocket.Chat authentication bypass via Apple Sign-In token replayhighCVSS 7.4
- CVE-2026-55666: Rocket.Chat account takeover via Apple OAuth login handlerinfoCVSS 9.3
- CVE-2026-49278: Rocket.Chat token disclosure and visitor impersonation in visitors.infomediumCVSS 6.7
- CVE-2026-49277: Rocket.Chat OAuth token persistence after account deactivationinfoCVSS 2.3
- CVE-2026-47733: Rocket.Chat XSS in ImageElement component via markdown imagesmediumCVSS 4.4
- CVE-2026-46423: Rocket.Chat authentication bypass in SAML signature validationinfoCVSS 9.3
- CVE-2026-45757: Rocket.Chat insufficient session expiration in idle deactivationinfoCVSS 2.3
- CVE-2026-45689: RocketChat Rocket.Chat NoSQL injection in OAuth2 token endpointcriticalCVSS 9.1
- CVE-2026-45688: Rocket.Chat NoSQL injection in CAS login handlercriticalCVSS 9.1
- CVE-2026-45687: Rocket.Chat mass assignment in sendFileMessage allows data export thefthighCVSS 8.5
- CVE-2026-45677: Rocket.Chat missing SAML signature verification in LogoutRequestinfoCVSS 8.7
- CVE-2026-48929: Rocket.Chat unauthenticated file deletion in deleteFileMessagehighCVSS 7.5EPSS 0.6%
- CVE-2026-48616: Rocket.Chat improper access control in Livechat file downloadscriticalCVSS 9.3EPSS 0.3%
- CVE-2026-32995: Rocket.Chat improper access control in autoTranslate.translateMessagehighCVSS 7.5
- CVE-2026-32994: Rocket.Chat improper access control in autotranslate APImediumCVSS 5.3
- CVE-2026-29198: Rocket.Chat NoSQL injection in OAuth token handlingcriticalCVSS 9.8
- CVE-2026-22560: Rocket.Chat open redirect in SAML SLO endpointmediumCVSS 5.3
- CVE-2024-46935: Rocket.Chat message parser denial of servicelowCVSS 3.1EPSS 0.6%
- CVE-2024-39713: Rocket.Chat Server-Side Request Forgery in Twilio webhooklowCVSS 3.1EPSS 3.2%
- CVE-2022-21830: Rocket.Chat Livechat cross-site scripting in message composerlowCVSS 3.1EPSS 0.8%
Most severe Rocket.chat vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-58066: Rocket.Chat authentication bypass in SAML SSOcriticalCVSS 9.8
- CVE-2026-29198: Rocket.Chat NoSQL injection in OAuth token handlingcriticalCVSS 9.8
- CVE-2026-48616: Rocket.Chat improper access control in Livechat file downloadscriticalCVSS 9.3EPSS 0.3%
- CVE-2026-45689: RocketChat Rocket.Chat NoSQL injection in OAuth2 token endpointcriticalCVSS 9.1
- CVE-2026-45688: Rocket.Chat NoSQL injection in CAS login handlercriticalCVSS 9.1
- CVE-2026-45687: Rocket.Chat mass assignment in sendFileMessage allows data export thefthighCVSS 8.5
- CVE-2026-55762: Rocket.Chat missing authorization in fingerprint REST endpointhighCVSS 8.1
- CVE-2026-48929: Rocket.Chat unauthenticated file deletion in deleteFileMessagehighCVSS 7.5EPSS 0.6%
- CVE-2026-65644: Rocket.Chat Omnichannel queue stored XSS via visitor namehighCVSS 7.5EPSS 0.5%
- CVE-2026-32995: Rocket.Chat improper access control in autoTranslate.translateMessagehighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 1 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 2 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/rocket-chat.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Rocket.chat vulnerabilities", https://junglewise.ai/threats/vendors/rocket-chat, 26 September 2026.