CVE-2026-58066: Critical Vulnerability in Rocket.Chat Allows Account Takeover
This text was generated using artificial intelligence (AI).On July 30, 2026, a critical security vulnerability was discovered in the Rocket.Chat communication platform, identified by the ID CVE-2026-58066 published. The vulnerability has a CVSS score of 9.8 This vulnerability affects the implementation of SAML Single Sign-On (SSO). It allows unauthenticated attackers to bypass authentication and take over any user account, including those with administrative privileges. The vendor has already released fixed versions.
Rocket.Chat has addressed several SAML-related security issues in recent years. In May 2026 alone, the vendor published two additional SAML advisories—including a case where signature validation was completely bypassed when the IdP certificate field was empty (GHSA-rgg7-qvp9-wvx7) and a lack of signature verification during logout (GHSA-pw6f-q8ww-vqfq). This recurring pattern underscores the importance of continuously monitoring the security status of third-party providers and the communication software in use.
The cause of the vulnerability lies in the improper processing of SAML responses used in the SSO process. Classified under CWE-347 (Improper Verification of Cryptographic Signature) The attack mechanism uses a technique known as XML Signature Wrapping (XSW) is known. CVSS score: 9.8 (Critical) — Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Although Rocket.Chat's SAML implementation validated the cryptographic signature within an XML message from a trusted identity provider (IdP), it failed to securely bind that validated signature to the actual identity data (samlp:Response / saml:Assertion) to bind.
An attacker can exploit this by embedding a validly signed SAML response within a manipulated XML structure. This outer structure contains forged user attributes, such as an administrator’s ID. The vulnerable Rocket.Chat instance processes the document, detects the valid signature, and incorrectly applies its trust status to the manipulated data controlled by the attacker. This results in a successful login as the spoofed user without requiring any login credentials.
This affects all self-hosted Rocket.Chat instances that use SAML SSO and are running one of the following versions:
Versions prior to 8.7.0
Versions prior to 8.6.1
Versions prior to 8.5.2
Versions prior to 8.4.5
Versions prior to 8.3.7
Versions prior to 8.2.7
Versions prior to 8.1.7
Versions prior to 8.0.8
Versions prior to October 7, 2014
Recommended countermeasures
Companies using Rocket.Chat should take immediate action to secure their systems. The following steps are required:
Breaking Update: The most important step is to update to one of the patched versions: 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8 or 7.10.14.
Configuration Check: Check the SAML SSO configuration and ensure that the identity provider's certificate is correctly configured to rule out related configuration errors.
Long-term monitoring: Establish a continuous vulnerability management process. This includes regularly reviewing security advisories from the vendor, which follows a 30-day disclosure policy under which updates may be provided before details are made public.
Note for companies in Germany and the EU: Anyone who self-hosts Rocket.Chat and uses SAML SSO should comply with the reporting requirement under Article 33 of the GDPR in the event of a personal data breach (deadline: 72 hours after becoming aware of the breach to the competent supervisory authority). Operators of critical infrastructure may also be subject to reporting obligations under NIS-2. The BSI generally recommends promptly applying security updates for critical vulnerabilities.
Classification by LocateRisk
The CVE-2026-58066 vulnerability highlights two key challenges for corporate IT security: the visibility of external attack surfaces and the risk posed by third-party software.
External Attack Surface Management (EASM): Rocket.Chat is often self-hosted and runs under an organization's domain (e.g.,. chat.companyname.de). Such instances can easily become „shadow IT“—that is, systems that are operated without central oversight and are overlooked during patch cycles. An EASM platform like LocateRisk continuously identifies all publicly accessible systems within an organization, including such Rocket.Chat servers. This visibility is the foundation for identifying affected systems in the first place and subsequently securing them.
Vendor Risk Management (VRM): If a service provider or partner uses a vulnerable Rocket.Chat instance for communication, this poses a supply chain risk. A compromise of the service provider can have a direct impact on your own organization—a pattern that is particularly evident in light of the recurring SAML vulnerabilities in Rocket.Chat. LocateRisk’s Cyber Vendor Risk Management continuously and automatically assesses the security posture of third-party providers. This allows risks in the supply chain to be identified early on, before they become a security issue for your own company.
LocateRisk is a solution developed and hosted in Germany that helps organizations comply with GDPR requirements and reduces the risk of access under the U.S. Cloud Act through German hosting.
CVE-2026-58066 is a critical vulnerability (CVSS 9.8) in Rocket.Chat’s SAML SSO implementation. It allows unauthenticated attackers to bypass the XML signature verification and log in as any user—including administrators—without possessing any credentials. The technique behind this is called XML Signature Wrapping (XSW) and is classified as CWE-347.
This affects self-hosted Rocket.Chat instances with SAML SSO that are older than the following patches: 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14. Users running any of these versions or a newer one are no longer vulnerable. Instances without SAML SSO configuration are not affected by this specific vulnerability.
The most important step is to immediately update to one of the patched versions. In addition, the SAML configuration—particularly the stored IdP certificate—should be checked for accuracy. Rocket.Chat typically publishes security advisories 30 days after a fix is released; you can subscribe to the official security advisories at github.com/RocketChat/Rocket.Chat/security helps identify potential vulnerabilities early on.
As of July 30, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.