PT-2026-50128 · Rocket.Chat · Rocket.Chat

CVE-2026-48616

·

Published

2026-06-16

·

Updated

2026-07-04

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 8.5.1 Rocket.Chat versions prior to 8.4.4 Rocket.Chat versions prior to 8.3.6 Rocket.Chat versions prior to 8.2.6 Rocket.Chat versions prior to 8.1.6 Rocket.Chat versions prior to 8.0.7 Rocket.Chat versions prior to 7.13.9 Rocket.Chat versions prior to 7.10.13
Description An access control issue exists in Livechat files. The endpoint '/file-upload/:fileId/:name' authorizes livechat access using rc room type=l with rc rid and rc token, but the authorization process fails to verify that the rc rid matches the rid of the requested file. Additionally, the :fileId variable is predictable due to sequential MongoDB IDs, and the :name variable can be any value, which allows unauthenticated discovery of all uploaded files.
Recommendations Update to version 8.5.1 Update to version 8.4.4 Update to version 8.3.6 Update to version 8.2.6 Update to version 8.1.6 Update to version 8.0.7 Update to version 7.13.9 Update to version 7.10.13

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48616

Affected Products

Rocket.Chat