CVE-2026-58066: Critical Vulnerability in Rocket.Chat Allows Account Takeover


This text was generated using artificial intelligence (AI).On July 30, 2026, a critical security vulnerability was discovered in the Rocket.Chat communication platform, identified by the ID CVE-2026-58066 published. The vulnerability has a CVSS score of 9.8 This vulnerability affects the implementation of SAML Single Sign-On (SSO). It allows unauthenticated attackers to bypass authentication and take over any user account, including those with administrative privileges. The vendor has already released fixed versions.

Rocket.Chat has addressed several SAML-related security issues in recent years. In May 2026 alone, the vendor published two additional SAML advisories—including a case where signature validation was completely bypassed when the IdP certificate field was empty (GHSA-rgg7-qvp9-wvx7) and a lack of signature verification during logout (GHSA-pw6f-q8ww-vqfq). This recurring pattern underscores the importance of continuously monitoring the security status of third-party providers and the communication software in use.

Are my systems affected? Check now →