CVE-2026-28514Disclosure(rocket.chat / rocket.chat)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch rocket.chat rocket.chat systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account service used in the ddp-streamer micro service that allows an attacker to log in to the service as any user with a password set, using any arbitrary password. The vulnerability stems from a missing await keyword when calling an asynchronous password validation function, causing a Promise object (which is always truthy) to be evaluated instead of the actual boolean validation result. This may lead to account takeover of any user whose username is known or guessable. This issue has been patched in versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rocket.chat

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-03-09)
  • 6 total mentions across 2 days

Affected systems

Products
rocket.chat

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-03-06: 2Mentions · 2026-03-09: 4PoC Mentioned / Linked · 2026-03-09: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-09: 303-0603-09
Signal classification4 categories
Disclosure
350.0%
General
116.7%
Patch
116.7%
PoC
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-062
General1Patch1
2026-03-094
Disclosure3PoC1
Full discourse6 posts
  • /r/netsec@_r_netsec
    Disclosure

    Sign in with ANY password into http://Rocket.Chat EE (CVE-2026-28514) and other vulnerabilities we’ve found with our open source AI framework https://github.blog/security/how-to-scan-for-vulnerabilities-with-github-security-labs-open-source-ai-powered-framework/

    Post summary

    The post announces a vulnerability (CVE-2026-28514) that allows authentication bypass in Rocket.Chat EE, discovered using an AI-powered vulnerability scanning framework.

    030661.5K
    32.8K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Sign in with ANY password into http://Rocket.Chat EE (CVE-2026-28514) and other vulnerabilities we’ve found with our open source AI framework https://github.blog/security/how-to-scan-for-vulnerabilities-with-github-security-labs-open-source-ai-powered-framework/

    Post summary

    The tweet highlights a discovered authentication bypass in Rocket.Chat EE (CVE-2026-28514) that allows sign‑in with any password, presenting a proof‑of‑concept without details on patches, exploitation tools, or active attacks.

    000161.3K
    152.5K followersView on X
  • David@DavidMarquet19
    Disclosure

    Sign in with ANY password into http://Rocket.Chat EE (CVE-2026-28514) and other vulnerabilities we’ve found with our open source AI framework https://tinyurl.com/2ahveext

    Post summary

    The post announces that CVE-2026-28514 allows authentication bypass in Rocket.Chat EE, but does not provide PoC, exploit code, or patch information.

    0000041
    167 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    Sign in with ANY password into http://Rocket.Chat EE (CVE-2026-28514) and other vulnerabilities we’ve found with our open source AI framework https://github.blog/security/how-to-scan-for-vulnerabilities-with-github-security-labs-open-source-ai-powered-framework/ https://t.co/lfokQHIIg4

    Post summary

    The tweet announces that CVE‑2026‑28514 allows authentication bypass by signing in with any password in Rocket.Chat EE, and references a blog about scanning vulnerabilities with an AI‑powered framework.

    0000076
    531 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28514 http://Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critic… https://www.cve.org/CVERecord?id=CVE-2026-28514

    Post summary

    The text references CVE-2026-28514 on Rocket.Chat and lists affected versions, but offers no substantive technical, exploit, or remediation details.

    00000100
    56.6K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-28514: http://Rocket.Chat flaw lets anyone sign in as any user; password check is skipped. Update to 7.13.3, 8.0.0 or later to block account takeover. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-28514 #RocketChat #infosec #AppSec

    Post summary

    The advisory highlights a sign‑in bypass flaw in Rocket.Chat and directs users to update to recent versions to remediate the issue.

    0000047
    51 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Approcket.chatrocket.chat---
Approcket.chatrocket.chat8.0.0--
Approcket.chatrocket.chat8.0.0--
Approcket.chatrocket.chat8.0.0--
Approcket.chatrocket.chat8.0.0--
Approcket.chatrocket.chat8.0.0--
Approcket.chatrocket.chat8.0.0--

Explore more