Authentication Vulnerability in Rocket.Chat Communication Platform
CVE-2026-30831
8HIGH
What is CVE-2026-30831?
Rocket.Chat is a customizable, open-source communication platform that suffered from authentication vulnerabilities within its enterprise DDP Streamer service. The Account.login method, exposed via DDP Streamer, failed to enforce Two-Factor Authentication (2FA) and did not verify the status of user accounts, allowing deactivated users to log in. These vital security checks are typically expected in standard Meteor login processes. The vulnerabilities have been addressed in subsequent software updates.
Affected Version(s)
Rocket.Chat < 7.10.8 < 7.10.8
Rocket.Chat < 7.11.5 < 7.11.5
Rocket.Chat < 7.12.5 < 7.12.5
