CVE-2026-58066

CRITICAL

Rocket.Chat - Improper Authentication

Title source: rule
STIX 2.1

Description

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.

Scores

CVSS v3 9.8
EPSS 0.0021
EPSS Percentile 11.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (9)
Rocket.Chat/Rocket.Chat < 7.10.14
Rocket.Chat/Rocket.Chat < 8.0.8
Rocket.Chat/Rocket.Chat < 8.1.7
Rocket.Chat/Rocket.Chat < 8.2.7
Rocket.Chat/Rocket.Chat < 8.3.7
Rocket.Chat/Rocket.Chat < 8.4.5
Rocket.Chat/Rocket.Chat < 8.5.2
Rocket.Chat/Rocket.Chat < 8.6.1
Rocket.Chat/Rocket.Chat < 8.7.0
Published Jul 30, 2026
Tracked Since Jul 30, 2026