Improper Authorization in Rocket.Chat Communication Platform
CVE-2026-55762
8.1HIGH
What is CVE-2026-55762?
Rocket.Chat, a customizable communications platform, has a vulnerability in its POST /api/v1/fingerprint endpoint that fails to validate user permissions properly. Authenticated users, including those with standard roles, can deregister a workspace by sending specific API requests. This action wipes cloud credentials, removes workspace licenses, and disrupts push notifications for all members. To regain access, a manual re-registration of the workspace is necessary. The issue is resolved in updates 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13.
Affected Version(s)
Rocket.Chat >= 8.5.0-rc.0, < 8.5.1 < 8.5.0-rc.0, 8.5.1
Rocket.Chat >= 8.4.0-rc.0, < 8.4.4 < 8.4.0-rc.0, 8.4.4
Rocket.Chat >= 8.3.0-rc.0, < 8.3.6 < 8.3.0-rc.0, 8.3.6
