Medium severity5.4NVD Advisory· Published Aug 10, 2026
CVE-2026-72918
CVE-2026-72918
Description
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated user to write arbitrary notification bodies because the sender is not checked, and the client-side UI can create an ephemeral fake message in another user's currently open chat. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <7.10.14, <8.0.8, <8.1.7, <8.2.7, <8.3.7, <8.4.5, <8.5.2, <8.6.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.