OAuth Token Management Flaw in Rocket.Chat by The Rocket.Chat Team
CVE-2026-49277

2.3LOW

Key Information:

Vendor

Rocketchat

Vendor
CVE Published:
24 June 2026

What is CVE-2026-49277?

Rocket.Chat, a widely-used open-source communication platform, has a security vulnerability where deactivated users retain the ability to use their existing OAuth tokens, including the ability to generate new access tokens from refresh tokens. This oversight allows unauthorized access, posing significant security risks. Users should upgrade to Rocket.Chat versions 8.5.0 or later to ensure any associated risks are mitigated.

Affected Version(s)

Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 < 8.5.0-rc.0, 8.5.0

Rocket.Chat >= 8.4.0-rc.0, < 8.4.2 < 8.4.0-rc.0, 8.4.2

Rocket.Chat >= 8.3.0-rc.0, < 8.3.4 < 8.3.0-rc.0, 8.3.4

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.