OAuth Token Management Flaw in Rocket.Chat by The Rocket.Chat Team
CVE-2026-49277
2.3LOW
What is CVE-2026-49277?
Rocket.Chat, a widely-used open-source communication platform, has a security vulnerability where deactivated users retain the ability to use their existing OAuth tokens, including the ability to generate new access tokens from refresh tokens. This oversight allows unauthorized access, posing significant security risks. Users should upgrade to Rocket.Chat versions 8.5.0 or later to ensure any associated risks are mitigated.
Affected Version(s)
Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 < 8.5.0-rc.0, 8.5.0
Rocket.Chat >= 8.4.0-rc.0, < 8.4.2 < 8.4.0-rc.0, 8.4.2
Rocket.Chat >= 8.3.0-rc.0, < 8.3.4 < 8.3.0-rc.0, 8.3.4
