Unauthenticated File Deletion Vulnerability in Rocket.Chat by Rocket.Chat
CVE-2026-48929
7.5HIGH
What is CVE-2026-48929?
Rocket.Chat contains a vulnerability that allows attackers to delete uploaded files without authentication. The flaw exists in the deleteFileMessage Meteor method, which executes file deletions via unauthenticated DDP WebSocket connections. This oversight leaks file IDs through public messages, enabling unauthorized users to delete any file stored in the system indiscriminately.
Affected Version(s)
Rocket.Chat 0 < 8.5.1
Rocket.Chat 0 < 8.4.4
Rocket.Chat 0 < 8.3.6
