WebSocket Vulnerability in Rocket.Chat Affects User Notifications
CVE-2026-72918

5.4MEDIUM

Key Information:

Vendor

Rocketchat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-72918?

The vulnerability in Rocket.Chat's WebSocket protocol allows authenticated users to send arbitrary notification bodies due to insufficient validation of the sender's identity. This flaw enables users to generate fake messages in other users' open chats, potentially leading to confusion and misuse of the communication platform. The issue has been addressed in the latest versions, ensuring improved security for all users.

Affected Version(s)

Rocket.Chat < 7.10.14 < 7.10.14

Rocket.Chat >= 8.0.0, < 8.0.8 < 8.0.0, 8.0.8

Rocket.Chat >= 8.1.0, < 8.1.7 < 8.1.0, 8.1.7

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.