Unauthenticated File Deletion Vulnerability in Rocket.Chat by Rocket.Chat
CVE-2026-48929

7.5HIGH

Key Information:

Vendor
CVE Published:
16 June 2026

What is CVE-2026-48929?

Rocket.Chat contains a vulnerability that allows attackers to delete uploaded files without authentication. The flaw exists in the deleteFileMessage Meteor method, which executes file deletions via unauthenticated DDP WebSocket connections. This oversight leaks file IDs through public messages, enabling unauthorized users to delete any file stored in the system indiscriminately.

Affected Version(s)

Rocket.Chat 0 < 8.5.1

Rocket.Chat 0 < 8.4.4

Rocket.Chat 0 < 8.3.6

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.