← Back

CVE-2026-48616

nvd nist
Published: Jun 17, 2026Modified: Jun 18, 2026

JSON object

Loading...
9.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.7
Source: support@hackerone.com (Secondary)

Description

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all uploaded files.

Affected (8)

1 product
Rocket.chat
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Rocket.chat
Before 7.10.13
From 7.13.0 to 7.13.9
From 8.0.0 to 8.0.7
From 8.1.0 to 8.1.6
From 8.2.0 to 8.2.6
From 8.3.0 to 8.3.6
From 8.4.0 to 8.4.4
From 8.5.0 to 8.5.1

References (2)

Source: support@hackerone.com
Issue TrackingPatchThird Party Advisory
Source: support@hackerone.com
Third Party Advisory

Timeline

No history available yet.