PT-2026-52116 · Unknown · Rocket.Chat

CVE-2026-55666

·

Published

2026-06-24

·

Updated

2026-09-01

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 8.5.1 Rocket.Chat versions prior to 8.4.4 Rocket.Chat versions prior to 8.3.6 Rocket.Chat versions prior to 8.2.6 Rocket.Chat versions prior to 8.1.6 Rocket.Chat versions prior to 8.0.7 Rocket.Chat versions prior to 7.10.13
Description In the handleIdentityToken() function within apps/meteor/app/apple/server/loginHandler.ts, the application parses a JSON Web Token (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—issued by Apple during the OAuth flow. If the JWT lacks an email parameter, the system incorrectly accepts an arbitrary email value provided directly in the request. This allows attackers to forge Apple JWTs without an email address to perform account takeover attacks.
Recommendations Update to version 8.5.1 Update to version 8.4.4 Update to version 8.3.6 Update to version 8.2.6 Update to version 8.1.6 Update to version 8.0.7 Update to version 7.10.13

Exploit

Fix

Improper Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55666
GHSA-WX3C-76RF-WPWF

Affected Products

Rocket.Chat