Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-65645

Quick assessment

Affected
Rocket.Chat Rocket.Chat
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Rocket.Chat 8.8.0 之前以及 8.7.1、8.6.2、8.5.3、8.4.6、8.3.8、8.2.8、8.1.8 和 7.10.15 版本中,Meteor DDP 方法 和 接受 和 作为原始、未加类型校验的参数,且未进行 schema 验证。攻击者可以用 MongoDB 操作符对象(例如 )替换字符串类型的房间 ID(room-id)或消息 ID(message-id)。尽管授权检查会将其解析为攻击者已有权限访问的某个房间,但后续的数据查询会跨所有房间展开,从而导致任何低权限认证用户都能泄露私

AI Predicted 6.5 Difficulty: Easy EPSS 0.14% · P4

Affected Version Matrix 9

VendorProduct Version RangeStatus
Rocket.Chat Rocket.Chat < 8.8.0 affected
< 8.7.1 affected
< 8.6.2 affected
< 8.5.3 affected
< 8.4.6 affected
< 8.3.8 affected
< 8.2.8 affected
< 8.1.8 affected
… +1 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-65645

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user. The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Rocket.Chat Rocket.Chat 0 ~ 8.8.0 -

II. Public POCs for CVE-2026-65645

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-65645

登录查看更多情报信息。

Patches & Fixes for CVE-2026-65645 (1)

News Coverage for CVE-2026-65645 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-65645

No comments yet


Leave a comment