CVE-2026-58066

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.
References
Link Resource
https://github.com/RocketChat/Rocket.Chat/pull/41233 Issue Tracking
https://hackerone.com/reports/3827674 Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-30 06:25

Updated : 2026-08-25 18:12


NVD link : CVE-2026-58066

Mitre link : CVE-2026-58066

CVE.ORG link : CVE-2026-58066


JSON object : View

Products Affected

rocket.chat

  • rocket.chat
CWE
CWE-287

Improper Authentication