OAuth Vulnerability in Rocket.Chat Affects Email Parameter Handling
CVE-2026-55666
9.3CRITICAL
What is CVE-2026-55666?
Rocket.Chat, a secure communications platform, has a vulnerability in its handling of Apple-issued JWTs during the OAuth authentication flow. In versions prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the application inadequately checks for an email parameter within the JWT. Without a valid email address, the system improperly processes arbitrary email values supplied by an attacker, enabling potential account takeover. This issue is resolved in the latest updates.
Affected Version(s)
Rocket.Chat >= 8.5.0-rc.0, < 8.5.1 < 8.5.0-rc.0, 8.5.1
Rocket.Chat >= 8.4.0-rc.0, < 8.4.4 < 8.4.0-rc.0, 8.4.4
Rocket.Chat >= 8.3.0-rc.0, < 8.3.6 < 8.3.0-rc.0, 8.3.6
