Authentication Bypass Vulnerability in Rocket.Chat Communication Platform
CVE-2026-45688

9.1CRITICAL

Key Information:

Vendor

Rocketchat

Vendor
CVE Published:
24 June 2026

What is CVE-2026-45688?

Rocket.Chat, the open-source communications platform, has a vulnerability in its CAS login handling prior to specified versions. An unauthenticated attacker can exploit this flaw by injecting MongoDB query operators into the expected opaque ticket string. This enables them to bypass the necessary CAS ticket verification, allowing them to match a legitimate credential token and gain unauthorized access, potentially escalating to full instance compromise if the victim user has administrative privileges. The vulnerability has been addressed in the latest product versions.

Affected Version(s)

Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 < 8.5.0-rc.0, 8.5.0

Rocket.Chat >= 8.4.0-rc.0, < 8.4.1 < 8.4.0-rc.0, 8.4.1

Rocket.Chat >= 8.3.0-rc.0, < 8.3.3 < 8.3.0-rc.0, 8.3.3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.