PT-2026-52096 · Rocket.Chat · Rocket.Chat

CVE-2026-46423

·

Published

2026-06-24

·

Updated

2026-06-26

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 8.5.0 Rocket.Chat versions prior to 8.4.1 Rocket.Chat versions prior to 8.3.3 Rocket.Chat versions prior to 8.2.3 Rocket.Chat versions prior to 8.1.4 Rocket.Chat versions prior to 8.0.5 Rocket.Chat versions prior to 7.13.7 Rocket.Chat versions prior to 7.10.11
Description The SAML service provider implementation fails to validate SAML Response and Assertion signatures when the IdP certificate field is left empty. This occurs because the verifySignatures() function returns early if serviceProviderOptions.cert is falsy, which is the default setting. Since the system only requires the SAML feature to be enabled and does not mandate a certificate, an administrator may inadvertently create a publicly accessible SAML login endpoint that accepts unsigned or attacker-supplied assertions, leading to an authentication bypass.
Recommendations Update to version 8.5.0 Update to version 8.4.1 Update to version 8.3.3 Update to version 8.2.3 Update to version 8.1.4 Update to version 8.0.5 Update to version 7.13.7 Update to version 7.10.11

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46423
GHSA-RGG7-QVP9-WVX7

Affected Products

Rocket.Chat