CVE-2026-72918
Rocket.Chat: Insecure implementation of websocket notifications
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated user to write arbitrary notification bodies because the sender is not checked, and the client-side UI can create an ephemeral fake message in another user's currently open chat. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1.
| CWE | CWE-862 |
| Vendor | rocketchat |
| Product | rocket.chat |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for rocketchat rocket.chat
Be the first to know when new medium vulnerabilities affecting rocketchat rocket.chat are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
RocketChat / Rocket.Chat
< 7.10.14 >= 8.0.0, < 8.0.8 >= 8.1.0, < 8.1.7 >= 8.2.0, < 8.2.7 >= 8.3.0, < 8.3.7 >= 8.4.0, < 8.4.5 >= 8.5.0, < 8.5.2 >= 8.6.0, < 8.6.1