CVE-2026-49277

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth bearer or refresh tokens when a user is deactivated. A deactivated user can continue using an existing OAuth access token, and can also mint a fresh access token from an existing refresh token. This vulnerability is fixed in 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-06-24 21:16

Updated : 2026-06-26 19:16


NVD link : CVE-2026-49277

Mitre link : CVE-2026-49277

CVE.ORG link : CVE-2026-49277


JSON object : View

Products Affected

No product.

CWE
CWE-613

Insufficient Session Expiration