PT-2026-52095 · Rocket.Chat · Rocket.Chat

CVE-2026-45757

·

Published

2026-06-24

·

Updated

2026-06-25

CVSS v4.0

2.3

Low

VectorAV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 8.5.0 Rocket.Chat versions prior to 8.4.2 Rocket.Chat versions prior to 8.3.4 Rocket.Chat versions prior to 8.2.4 Rocket.Chat versions prior to 8.1.5 Rocket.Chat versions prior to 8.0.6 Rocket.Chat versions prior to 7.13.8 Rocket.Chat versions prior to 7.10.12
Description Rocket.Chat allows users who have been deactivated via the users.deactivateIdle function to continue using previously issued login tokens. This allows a user marked as inactive for idleness by an administrator to maintain access to authenticated REST endpoints.
Recommendations Update to version 8.5.0 Update to version 8.4.2 Update to version 8.3.4 Update to version 8.2.4 Update to version 8.1.5 Update to version 8.0.6 Update to version 7.13.8 Update to version 7.10.12

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45757
GHSA-6G3W-VG5P-W892

Affected Products

Rocket.Chat