Improper Authorization in Rocket.Chat Communication Platform
CVE-2026-55762

8.1HIGH

Key Information:

Vendor

Rocketchat

Vendor
CVE Published:
24 June 2026

What is CVE-2026-55762?

Rocket.Chat, a customizable communications platform, has a vulnerability in its POST /api/v1/fingerprint endpoint that fails to validate user permissions properly. Authenticated users, including those with standard roles, can deregister a workspace by sending specific API requests. This action wipes cloud credentials, removes workspace licenses, and disrupts push notifications for all members. To regain access, a manual re-registration of the workspace is necessary. The issue is resolved in updates 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13.

Affected Version(s)

Rocket.Chat >= 8.5.0-rc.0, < 8.5.1 < 8.5.0-rc.0, 8.5.1

Rocket.Chat >= 8.4.0-rc.0, < 8.4.4 < 8.4.0-rc.0, 8.4.4

Rocket.Chat >= 8.3.0-rc.0, < 8.3.6 < 8.3.0-rc.0, 8.3.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.