CVE-2026-45757

LOW

Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens

Title source: cna
STIX 2.1

Description

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through users.deactivateIdle to keep using already-issued login tokens. A user that an administrator has marked inactive for idleness can still access authenticated REST endpoints with the old token. This vulnerability is fixed in 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.

References (1)

Core 1
Core References

Scores

CVSS v4 2.3
EPSS 0.0022
EPSS Percentile 12.0%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (8)
RocketChat/Rocket.Chat < 7.10.12
RocketChat/Rocket.Chat >= 7.11.0-rc.0, < 7.13.8
RocketChat/Rocket.Chat >= 8.0.0-rc.0, < 8.0.6
RocketChat/Rocket.Chat >= 8.1.0-rc.0, < 8.1.5
RocketChat/Rocket.Chat >= 8.2.0-rc.0, < 8.2.4
RocketChat/Rocket.Chat >= 8.3.0-rc.0, < 8.3.4
RocketChat/Rocket.Chat >= 8.4.0-rc.0, < 8.4.2
RocketChat/Rocket.Chat >= 8.5.0-rc.0, < 8.5.0
Published Jun 24, 2026
Tracked Since Jun 25, 2026