Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth bearer or refresh tokens when a user is deactivated. A deactivated user can continue using an existing OAuth access token, and can also mint a fresh access token from an existing refresh token. This vulnerability is fixed in 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.
CVSS
No CVSS.
References
Configurations
No configuration.
History
24 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-24 21:16
Updated : 2026-06-26 19:16
NVD link : CVE-2026-49277
Mitre link : CVE-2026-49277
CVE.ORG link : CVE-2026-49277
JSON object : View
Products Affected
No product.
CWE
CWE-613
Insufficient Session Expiration
