CRITICAL🇵🇱 Wersja polska

CVE-2026-45688

CVSS 9.1v3.1pub. 2026-06-24upd. 2026-06-26

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login handler forwards the client-supplied options.cas.credentialToken value straight into a MongoDB findOne({_id: ...}) query without any runtime type check. TypeScript's string parameter annotation is erased at runtime, so an unauthenticated attacker can substitute a MongoDB query operator ({"$gt": ""}, {"$ne": null}, etc.) for what the server expects to be an opaque ticket string. The injected operator matches the first unexpired document in the credential_tokens collection, bypassing the CAS ticket check entirely. When any legitimate CAS or SAML SSO login is in flight, the attacker's next DDP login call matches the same credential-token row via the NoSQL operator and is issued a full Meteor auth token (userId + token) bound to the victim. The token is immediately usable against the complete REST and DDP surface as that user. If the victim is an administrator, this escalates to full instance compromise via Apps-Engine app install. This vulnerability is fixed in 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11.

🤖 AI Analysis
How it works

The CAS login handler passes the value of the options.cas.credentialToken parameter directly to the MongoDB findOne({_id: ...}) query without any runtime type verification. The TypeScript type annotation for string is removed during compilation and provides no protection in the runtime environment. An attacker can inject a MongoDB query operator (e.g., {"$gt": ""} or {"$ne": null}) instead of the expected ticket string. The injected operator matches the first invalid (irrelevant) document in the credential_tokens collection, and if a legitimate CAS or SAML login by another user is in progress at the same time, the next DDP login call by the attacker matches the same record and obtains the full Meteor authentication token (userId + token) associated with the victim.

Impact

The attacker obtains a full Meteor authentication token assigned to the victim's account, giving them access to the entire REST and DDP interface as that user. In case of compromising an administrator account, complete compromise of the instance is possible, including installation of malicious applications through Apps-Engine.

Mitigation & patch

Rocket.Chat should be updated to one of the following versions containing the fix: 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, or 7.10.11. Until updating, it is recommended to consider temporarily disabling CAS/SAML SSO integration if operationally feasible.

Who is affected

Rocket.Chat in versions prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11 that use the CAS login mechanism.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References