CVE-2026-72918: Rocket.Chat: Insecure implementation of websocket notifications
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated user to write arbitrary notification bodies because the sender is not checked, and the client-side UI can create an ephemeral fake message in another user's currently open chat. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.10.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.1.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.2.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.3.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.4.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.5.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72918?
The severity of CVE-2026-72918 is classified as medium with a CVSS score of 5.4.
How do I fix CVE-2026-72918?
To fix CVE-2026-72918, you should upgrade Rocket.Chat to versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, or 8.6.1 or later.
What vulnerability does CVE-2026-72918 address?
CVE-2026-72918 addresses the insecure implementation of websocket notifications that allows authenticated users to write arbitrary notification bodies.
Who is affected by CVE-2026-72918?
CVE-2026-72918 affects all versions of Rocket.Chat prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1.
What impact does CVE-2026-72918 have on security?
CVE-2026-72918 can potentially lead to unauthorized manipulation of notification messages, affecting user experience and trust.