2.3
/ 10
LOW
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through users.deactivateIdle to keep using already-issued login tokens. A user that an administrator has marked inactive for idleness can still access authenticated REST endpoints with the old token. This vulnerability is fixed in 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.
Basic Information
ID
CVE-2026-45757
Source
GitHub_M
Published
Jun 24, 2026 at 21:01
Modified
Jun 24, 2026 at 21:02
Affected Product
Vendor
RocketChat
Product
Rocket.Chat
Version
>= 8.5.0-rc.0, < 8.5.0
Affected Versions
RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.0
RocketChat Rocket.Chat >= 8.4.0-rc.0, < 8.4.2
RocketChat Rocket.Chat >= 8.3.0-rc.0, < 8.3.4
RocketChat Rocket.Chat >= 8.2.0-rc.0, < 8.2.4
RocketChat Rocket.Chat >= 8.1.0-rc.0, < 8.1.5
RocketChat Rocket.Chat >= 8.0.0-rc.0, < 8.0.6
RocketChat Rocket.Chat >= 7.11.0-rc.0, < 7.13.8
RocketChat Rocket.Chat < 7.10.12
RocketChat Rocket.Chat >= 8.4.0-rc.0, < 8.4.2
RocketChat Rocket.Chat >= 8.3.0-rc.0, < 8.3.4
RocketChat Rocket.Chat >= 8.2.0-rc.0, < 8.2.4
RocketChat Rocket.Chat >= 8.1.0-rc.0, < 8.1.5
RocketChat Rocket.Chat >= 8.0.0-rc.0, < 8.0.6
RocketChat Rocket.Chat >= 7.11.0-rc.0, < 7.13.8
RocketChat Rocket.Chat < 7.10.12