CVE-2026-55666Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in apps/meteor/app/apple/server/loginHandler.ts, handleIdentityToken parses a JWT issued by Apple during the OAuth flow. The try block checks for an email parameter. If the JWT does not contain an email address, the application falls back to accepting an arbitrary email value supplied directly in the request. Attackers are able to forge Apple JWTs that do not contain an email address and leverage this vulnerability to carry out account takeover attacks. This vulnerability is fixed in 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-01); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-29: 1Mentions · 2026-07-01: 2Mentions · 2026-09-01: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-01: 1Technical Details · 2026-09-01: 106-2907-0109-01
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-291
Patch1
2026-07-012
Disclosure1Patch1
2026-09-011
Disclosure1
Full discourse4 posts
  • Hacktron AI@HacktronAI
    Disclosure

    Human attention is finite. @RocketChat runs every pull request through Hacktron so security review keeps pace with shipping. In 20 days: 155 PRs reviewed, 17 real vulnerabilities found, including CVE-2026-55666, a critical Apple OAuth account takeover. Read the full story: https://www.hacktron.ai/customer-stories/rocketchat?utm_source=x&utm_medium=social&utm_campaign=customer-stories&utm_content=rocketchat-repost

    Post summary

    RocketChat’s security review process uncovered CVE-2026-55666, a critical Apple OAuth account takeover vulnerability, yet no proof‑of‑concept, exploit code, or patch details are included.

    15036103.8K
    9.6K followersView on X
  • Hacktron AI@HacktronAI
    Patch

    Hacktron now powers security review for every pull request in @RocketChat. In the first 20 days of integration, Rocket․Chat has found and fixed 17 real vulnerabilities, including a critical-severity account takeover (CVE-2026-55666), and a token replay attack (CVE-2026-55759). https://t.co/BCwcl6S2jZ

    Post summary

    Hacktron reports having identified and patched 17 vulnerabilities in RocketChat, including a critical account‑takeover CVE‑2026‑55666 and a token replay CVE‑2026‑55759, with no evidence of proofs of concept or active exploitation.

    1301052.0K
    4.7K followersView on X
  • s1r1us (mohan)@S1r1u5_
    Disclosure

    Bug 1: Full Account Takeover This is the first vulnerability Hacktron found right after http://Rocket.Chat integrated it into their workflows, and it’s a very elegant and critical bug. This affected existing code, so got CVE-2026-55666. https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-wx3c-76rf-wpwf

    Post summary

    Hacktron disclosed a new critical full account takeover vulnerability in Rocket.Chat (CVE-2026-55666) via a GitHub advisory, but no PoC, exploit, or patch details were provided.

    10020489
    15.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Flawed authentication mechanism in #rocket.chat can lead to account takeover and data theft. For more information about the #CVE-2026-55666, visit https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-wx3c-76rf-wpwf #Patch #Patch #Patch

    Post summary

    The tweet warns about CVE‑2026‑55666’s authentication flaw and points to a patch advisory, indicating that mitigation information is available.

    00000303
    7.2K followersView on X

Explore more