Authentication Bypass Vulnerability in Rocket.Chat
CVE-2026-28514
What is CVE-2026-28514?
CVE-2026-28514 is a critical authentication bypass vulnerability affecting Rocket.Chat, an open-source communication platform designed for secure and customizable interactions among users. The flaw resides within the account service of the ddp-streamer microservice, which is responsible for handling user authentication. Due to a programming oversight—specifically, the omission of an await keyword in an asynchronous password validation function—any attacker who possesses or can guess a username can authenticate as that user by supplying any arbitrary password. This vulnerability poses a significant risk to organizations utilizing Rocket.Chat for communication, as it can lead to unauthorized account access and possible data breaches.
Potential impact of CVE-2026-28514
-
Account Takeover: Attackers can gain unauthorized access to user accounts, leading to potential misuse of sensitive information and unauthorized actions within the platform.
-
Data Breach: With the capability to impersonate legitimate users, threats to the confidentiality, integrity, and availability of organizational data can increase significantly, potentially resulting in data leaks.
-
Reputation Damage: Organizations may suffer reputational harm due to compromised accounts, particularly if sensitive communications or personal information are exposed, causing loss of customer trust and business integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Rocket.Chat < 7.8.6 < 7.8.6
Rocket.Chat < 7.9.8 < 7.9.8
Rocket.Chat < 7.10.7 < 7.10.7
