PT-2026-81147 · Rocket.Chat · Rocket.Chat

·

CVE-2026-75575

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat (affected versions not specified)
Description An unauthenticated caller can repeatedly invoke the sendForgotPasswordEmail Meteor method because it lacks a DDP rate limit. This method is accessible via DDP and the HTTP endpoint 'POST /api/v1/method.callAnon/sendForgotPasswordEmail'. Exploitation allows an attacker to send an unlimited volume of password reset emails to a specific address using the system's mail sender. Additionally, the method can be used to probe for accounts; it returns true for addresses without an account or for successful sends, but returns false for accounts using external providers when Accounts AllowPasswordChangeForOAuthUsers is disabled, allowing an attacker to identify those specific account types.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75575
GHSA-7C6V-M68V-V73R

Affected Products

Rocket.Chat