CVE-2026-55759General

LOWCVSS 7.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-In handler verifies JWT signatures but skips claims validation. Any Apple-signed JWT with a non-empty iss is accepted regardless of aud, exp, nbf, or nonce. An attacker who obtains a target user's Apple identity token (from server logs, an intercepted sign-in flow, or another application sharing the same Apple developer team) can replay it to authenticate as that user, with no expiration on the replay window. This vulnerability is fixed in 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-294

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-01: 2Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 207-01
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Hacktron AI@HacktronAI
    Patch

    Hacktron now powers security review for every pull request in @RocketChat. In the first 20 days of integration, Rocket․Chat has found and fixed 17 real vulnerabilities, including a critical-severity account takeover (CVE-2026-55666), and a token replay attack (CVE-2026-55759). https://t.co/BCwcl6S2jZ

    Post summary

    The Hacktron integration into Rocket.Chat identified and patched multiple CVEs, including a critical account takeover and token replay vulnerability.

    1301052.0K
    4.7K followersView on X
  • s1r1us (mohan)@S1r1u5_
    General

    Bug 2: Account takeover via token replay Hacktron catches regressions too. This Apple sign-in bug (CVE-2026-55759) showed up before and it caught it, then it caught the same class of issue coming back in a new PR. https://github.com/RocketChat/Rocket.Chat/pull/40721#discussion_r3460145622

    Post summary

    The tweet notes that CVE-2026-55759, an Apple sign‑in token replay flaw, resurfaced in a new pull request, signaling a recurring regression but offering no PoC, exploit, or patch details.

    101213.0K
    13.9K followersView on X

Explore more