CVE-2026-58066
A security flaw in Rocket.Chat's SAML Single Sign-On (SSO) feature allows attackers to bypass authentication. By submitting a specially crafted document, an attacker can trick the system into recognizing them as any user.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Rocket.Chat versions prior to 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 who use SAML Single Sign-On (SSO).
Real-world impact
An attacker could gain unauthorized access to any account on a Rocket.Chat server, potentially allowing them to impersonate administrators or access sensitive communications.
Why this severity
This is a critical vulnerability because it can be exploited remotely over the internet without any user interaction or special privileges, leading to a total compromise of user identity within the application.
What to do about it
- 01Upgrade Rocket.Chat to version 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, or 7.10.14 or later.
NVD-referenced vendor advisory
Timeline
- Jul 30, 2026 · 5h agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 4h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.