PT-2026-52116 · Unknown · Rocket.Chat
CVE-2026-55666
·
Published
2026-06-24
·
Updated
2026-09-01
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Rocket.Chat versions prior to 8.5.1
Rocket.Chat versions prior to 8.4.4
Rocket.Chat versions prior to 8.3.6
Rocket.Chat versions prior to 8.2.6
Rocket.Chat versions prior to 8.1.6
Rocket.Chat versions prior to 8.0.7
Rocket.Chat versions prior to 7.10.13
Description
In the
handleIdentityToken() function within apps/meteor/app/apple/server/loginHandler.ts, the application parses a JSON Web Token (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—issued by Apple during the OAuth flow. If the JWT lacks an email parameter, the system incorrectly accepts an arbitrary email value provided directly in the request. This allows attackers to forge Apple JWTs without an email address to perform account takeover attacks.Recommendations
Update to version 8.5.1
Update to version 8.4.4
Update to version 8.3.6
Update to version 8.2.6
Update to version 8.1.6
Update to version 8.0.7
Update to version 7.10.13
Exploit
Fix
Improper Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rocket.Chat