CVE-2026-72919: Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated registered user with the create-team permission to convert an unrelated public channel by supplying channelName instead of channelId because the edit-room permission is checked only for channelId. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.10.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.1.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.2.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.3.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.4.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.5.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72919?
The severity of CVE-2026-72919 is classified as medium with a score of 4.3.
How do I fix CVE-2026-72919?
To fix CVE-2026-72919, you should upgrade to versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, or 8.6.1 of Rocket.Chat.
What kind of vulnerability is CVE-2026-72919?
CVE-2026-72919 is a broken access control vulnerability that allows unauthorized conversion of public channels into teams.
Who is affected by CVE-2026-72919?
Authenticated registered users with the create-team permission in Rocket.Chat versions prior to the specified fixes are affected by CVE-2026-72919.
What is the attack vector for CVE-2026-72919?
The attack vector for CVE-2026-72919 is that it can be exploited over the network by authenticated users.