PT-2026-52096 · Rocket.Chat · Rocket.Chat
CVE-2026-46423
·
Published
2026-06-24
·
Updated
2026-06-26
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Rocket.Chat versions prior to 8.5.0
Rocket.Chat versions prior to 8.4.1
Rocket.Chat versions prior to 8.3.3
Rocket.Chat versions prior to 8.2.3
Rocket.Chat versions prior to 8.1.4
Rocket.Chat versions prior to 8.0.5
Rocket.Chat versions prior to 7.13.7
Rocket.Chat versions prior to 7.10.11
Description
The SAML service provider implementation fails to validate SAML Response and Assertion signatures when the IdP certificate field is left empty. This occurs because the
verifySignatures() function returns early if serviceProviderOptions.cert is falsy, which is the default setting. Since the system only requires the SAML feature to be enabled and does not mandate a certificate, an administrator may inadvertently create a publicly accessible SAML login endpoint that accepts unsigned or attacker-supplied assertions, leading to an authentication bypass.Recommendations
Update to version 8.5.0
Update to version 8.4.1
Update to version 8.3.3
Update to version 8.2.3
Update to version 8.1.4
Update to version 8.0.5
Update to version 7.13.7
Update to version 7.10.11
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocket.Chat