CVE-2026-45757
LOWRocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens
Title source: cnaDescription
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through users.deactivateIdle to keep using already-issued login tokens. A user that an administrator has marked inactive for idleness can still access authenticated REST endpoints with the old token. This vulnerability is fixed in 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-6g3w-vg5p-w892
Scores
CVSS v4
2.3
EPSS
0.0022
EPSS Percentile
12.0%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-613
Status
published
Products (8)
RocketChat/Rocket.Chat
< 7.10.12
RocketChat/Rocket.Chat
>= 7.11.0-rc.0, < 7.13.8
RocketChat/Rocket.Chat
>= 8.0.0-rc.0, < 8.0.6
RocketChat/Rocket.Chat
>= 8.1.0-rc.0, < 8.1.5
RocketChat/Rocket.Chat
>= 8.2.0-rc.0, < 8.2.4
RocketChat/Rocket.Chat
>= 8.3.0-rc.0, < 8.3.4
RocketChat/Rocket.Chat
>= 8.4.0-rc.0, < 8.4.2
RocketChat/Rocket.Chat
>= 8.5.0-rc.0, < 8.5.0
Published
Jun 24, 2026
Tracked Since
Jun 25, 2026