CVE-2026-48616

CRITICAL CVSS 3.0: 9.3 EPSS 0.33%
Updated Jun 18, 2026
Rocket.Chat
Parameter Value
CVSS 9.3 (CRITICAL)
Affected Versions 7.13.0 — 8.5.1
Fixed In 7.10.13
Type CWE-284 (Improper Access Control)
Vendor Rocket.Chat
Public PoC No

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all uploaded files.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.0

Vulnerable Products 8

Configuration From (including) Up to (excluding)
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
7.10.13
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
7.13.0 7.13.9
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.0.0 8.0.7
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.1.0 8.1.6
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.2.0 8.2.6
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.3.0 8.3.6
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.4.0 8.4.4
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.5.0 8.5.1