CVE Vulnerabilities

CVE-2026-30831

Improper Authentication

Published: Mar 06, 2026 | Modified: Mar 13, 2026
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chats enterprise DDP Streamer service. The Account.login method exposed through the DDP Streamer does not enforce Two-Factor Authentication (2FA) or validate user account status (deactivated users can still login), despite these checks being mandatory in the standard Meteor login flow. This issue has been patched in versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Rocket.chatRocket.chat*7.10.8 (excluding)
Rocket.chatRocket.chat7.11.0 (including)7.11.5 (excluding)
Rocket.chatRocket.chat7.12.0 (including)7.12.5 (excluding)
Rocket.chatRocket.chat7.13.0 (including)7.13.4 (excluding)
Rocket.chatRocket.chat8.0.0 (including)8.0.2 (excluding)
Rocket.chatRocket.chat8.1.0 (including)8.1.1 (excluding)
Rocket.chatRocket.chat8.2.0-rc0 (including)8.2.0-rc0 (including)
Rocket.chatRocket.chat8.2.0-rc1 (including)8.2.0-rc1 (including)
Rocket.chatRocket.chat8.2.0-rc2 (including)8.2.0-rc2 (including)

Potential Mitigations

References