PT-2026-52091 · Rocket.Chat · Rocket.Chat
CVE-2026-45677
·
Published
2026-06-24
·
Updated
2026-06-24
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Rocket.Chat versions prior to 8.5.0
Rocket.Chat versions prior to 8.4.1
Rocket.Chat versions prior to 8.3.3
Rocket.Chat versions prior to 8.2.3
Rocket.Chat versions prior to 8.1.4
Rocket.Chat versions prior to 8.0.5
Rocket.Chat versions prior to 7.13.7
Rocket.Chat versions prior to 7.10.11
Description
The SAML integration fails to verify the signature on inbound LogoutRequest messages. An unauthenticated remote attacker who knows a target user's SAML NameID (often the user's email address) can submit a crafted unsigned LogoutRequest to the SP logout endpoint. The server processes this request as legitimate and destroys the victim's session. This can be automated to target multiple accounts, potentially rendering the platform unusable for SAML-authenticated users.
Recommendations
Update to version 8.5.0
Update to version 8.4.1
Update to version 8.3.3
Update to version 8.2.3
Update to version 8.1.4
Update to version 8.0.5
Update to version 7.13.7
Update to version 7.10.11
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocket.Chat