CVE-2026-65645Disclosure(rocket.chat / rocket.chat)

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user. The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rocket.chat

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
rocket.chat

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Technical Details · 2026-08-21: 108-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-65645 http://Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept… https://www.cve.org/CVERecord?id=CVE-2026-65645 ----- Traducción: CVE-20… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-65645 for certain Rocket.Chat versions, links to the CVE record, but provides no PoC, exploit, patch, or technical details.

    0000025
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-65645 http://Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept… https://www.cve.org/CVERecord?id=CVE-2026-65645

    Post summary

    The snippet highlights a CVE affecting specific Rocket.Chat releases, naming the vulnerable Meteor DDP methods, but provides no exploit, patch, or active exploitation details.

    00000550
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-65645 http://Rocket.Chat DDP Method Vulnerability Exposes Private Thread Data https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-65645

    Post summary

    The text announces CVE-2026-65645, a Rocket.Chat DDP vulnerability that exposes private thread data, but provides no PoC, exploit, or patch information.

    0000099
    4.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Approcket.chatrocket.chat---
Approcket.chatrocket.chat8.7.0--

Explore more