Authentication Bypass Vulnerability in Rocket.Chat
CVE-2026-28514

9.3CRITICAL

Key Information:

Vendor

Rocketchat

Vendor
CVE Published:
6 March 2026

What is CVE-2026-28514?

CVE-2026-28514 is a critical authentication bypass vulnerability affecting Rocket.Chat, an open-source communication platform designed for secure and customizable interactions among users. The flaw resides within the account service of the ddp-streamer microservice, which is responsible for handling user authentication. Due to a programming oversight—specifically, the omission of an await keyword in an asynchronous password validation function—any attacker who possesses or can guess a username can authenticate as that user by supplying any arbitrary password. This vulnerability poses a significant risk to organizations utilizing Rocket.Chat for communication, as it can lead to unauthorized account access and possible data breaches.

Potential impact of CVE-2026-28514

  1. Account Takeover: Attackers can gain unauthorized access to user accounts, leading to potential misuse of sensitive information and unauthorized actions within the platform.

  2. Data Breach: With the capability to impersonate legitimate users, threats to the confidentiality, integrity, and availability of organizational data can increase significantly, potentially resulting in data leaks.

  3. Reputation Damage: Organizations may suffer reputational harm due to compromised accounts, particularly if sensitive communications or personal information are exposed, causing loss of customer trust and business integrity.

Affected Version(s)

Rocket.Chat < 7.8.6 < 7.8.6

Rocket.Chat < 7.9.8 < 7.9.8

Rocket.Chat < 7.10.7 < 7.10.7

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.