Authentication Vulnerability in Rocket.Chat Communication Platform
CVE-2026-30831

8HIGH

Key Information:

Vendor

Rocketchat

Vendor
CVE Published:
6 March 2026

What is CVE-2026-30831?

Rocket.Chat is a customizable, open-source communication platform that suffered from authentication vulnerabilities within its enterprise DDP Streamer service. The Account.login method, exposed via DDP Streamer, failed to enforce Two-Factor Authentication (2FA) and did not verify the status of user accounts, allowing deactivated users to log in. These vital security checks are typically expected in standard Meteor login processes. The vulnerabilities have been addressed in subsequent software updates.

Affected Version(s)

Rocket.Chat < 7.10.8 < 7.10.8

Rocket.Chat < 7.11.5 < 7.11.5

Rocket.Chat < 7.12.5 < 7.12.5

References

CVSS V4

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.