CVE-2026-45677: fallo de gravedad alta en RocketChat Rocket.Chat
Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.7epss 0.7%
probabilidad de explotación
0.7%top 49% de las CVE
explotación observada
noninguna fuente lo reporta
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML integration does not verify the signature on inbound LogoutRequest messages. An unauthenticated remote attacker who knows a target user's SAML NameID - which major identity providers (Okta, Google Workspace, Microsoft Entra ID, JumpCloud) expose as the user's email address - can craft a valid-looking unsigned LogoutRequest and submit it to the SP logout endpoint. The server processes it as legitimate, immediately destroying the victim's session. Because the attack requires no authentication and no interaction from the victim, it can be repeated in a loop against individual users or scripted across many accounts, effectively rendering the Rocket.Chat instance unusable for SAML-authenticated users. This vulnerability is fixed in 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
RocketChat · Rocket.ChatCVEs relacionadas — RocketChat Rocket.Chat
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-32832MEDIUMReDOS in Rocket.ChatEPSS 1.6%CVE-2026-28514CRITICALRocket.Chat: Users can login with any password via the EE ddp-streamer-serviceEPSS 0.8%CVE-2026-30831HIGHRocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamerEPSS 0.6%CVE-2026-45689CRITICALRocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATOEPSS 0.5%CVE-2026-45688CRITICALRocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session HijackEPSS 0.5%CVE-2026-55762HIGHRocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` EndpointEPSS 0.5%