HIGH🇬🇧 English

CVE-2026-30831

CVSS 8.0v4.0pub. 2026-03-06upd. 2026-03-13

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer service. The Account.login method exposed through the DDP Streamer does not enforce Two-Factor Authentication (2FA) or validate user account status (deactivated users can still login), despite these checks being mandatory in the standard Meteor login flow. This issue has been patched in versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Rocket.chat

    APP
    Rocket.Chat
    8.2.07.11.0 – 7.11.5 (bez)7.12.0 – 7.12.5 (bez)< 7.10.88.0.0 – 8.0.2 (bez)8.1.0 – 8.1.1 (bez)7.13.0 – 7.13.4 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2026-58066CRITICAL9.8PL ✓ten sam produkt

Rocket.Chat SAML SSO — Auth Bypass przez brak wiązania podpisu XML

CVE-2026-48616CRITICAL9.3PL ✓ten sam produkt

Rocket.Chat — podatność access control w plikach Livechat (nieautoryzowany dostęp)

CVE-2026-29198CRITICAL9.8PL ✓ten sam produkt

Rocket.Chat — NoSQL injection umożliwiający przejęcie konta (SQLi)

CVE-2026-28514CRITICAL9.3PL ✓ten sam produkt

Rocket.Chat — pominięcie await powoduje auth bypass w ddp-streamer

CVE-2023-28316CRITICAL9.8PL ✓ten sam produkt

Rocket.Chat: brak unieważnienia sesji po aktywacji 2FA