Authentication Bypass Vulnerability in Rocket.Chat by Rocket.Chat
CVE-2026-55759
What is CVE-2026-55759?
Rocket.Chat, a widely used open-source communication platform, has a vulnerability affecting its handling of Apple Sign-In. Prior to specific versions, the platform's JWT signature verification process fails to validate certain claims. This allows an attacker to exploit any valid Apple-signed JWT with a non-empty issuer, bypassing key validation checks. If an attacker gains access to a target user's Apple identity token—potentially through server logs or intercepted sign-in processes—they can authenticate as that user without any limitation on the replay window. This significant security issue highlights the need for prompt updates to the affected versions of Rocket.Chat, as remedial measures have been implemented in subsequent releases.
Affected Version(s)
Rocket.Chat >= 8.5.0-rc.0, < 8.5.1 < 8.5.0-rc.0, 8.5.1
Rocket.Chat >= 8.4.0-rc.0, < 8.4.4 < 8.4.0-rc.0, 8.4.4
Rocket.Chat >= 8.3.0-rc.0, < 8.3.6 < 8.3.0-rc.0, 8.3.6
