PT-2026-52091 · Rocket.Chat · Rocket.Chat

CVE-2026-45677

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 8.5.0 Rocket.Chat versions prior to 8.4.1 Rocket.Chat versions prior to 8.3.3 Rocket.Chat versions prior to 8.2.3 Rocket.Chat versions prior to 8.1.4 Rocket.Chat versions prior to 8.0.5 Rocket.Chat versions prior to 7.13.7 Rocket.Chat versions prior to 7.10.11
Description The SAML integration fails to verify the signature on inbound LogoutRequest messages. An unauthenticated remote attacker who knows a target user's SAML NameID (often the user's email address) can submit a crafted unsigned LogoutRequest to the SP logout endpoint. The server processes this request as legitimate and destroys the victim's session. This can be automated to target multiple accounts, potentially rendering the platform unusable for SAML-authenticated users.
Recommendations Update to version 8.5.0 Update to version 8.4.1 Update to version 8.3.3 Update to version 8.2.3 Update to version 8.1.4 Update to version 8.0.5 Update to version 7.13.7 Update to version 7.10.11

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45677
GHSA-PW6F-Q8WW-VQFQ

Affected Products

Rocket.Chat