CVE-2026-58066 Details
Description
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.
A vulnerability in Rocket.Chat's SAML Single Sign-On (SSO) implementation prior to versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 allows for authentication bypass through XML signature wrapping. While the SSO process verified XML signatures, it failed to properly bind the validated signature to the 'samlp:Response' or 'saml:Assertion' elements. This oversight enables an attacker to submit a wrapped document with forged identity attributes, using any valid signature from a trusted Identity Provider (IdP) certificate, to log in as an arbitrary user.
Users can update to Rocket.Chat versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, or 7.10.14 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/RocketChat/Rocket.Chat/pull/41233 | [email protected] | Issue Tracking |
| https://hackerone.com/reports/3827674 | [email protected] | Third Party AdvisoryIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rocket.chat rocket.chat | < 7.10.14 >= 8.0.0, < 8.0.8 >= 8.1.0, < 8.1.7 >= 8.2.0, < 8.2.7 >= 8.3.0, < 8.3.7 >= 8.4.0, < 8.4.5 >= 8.5.0, < 8.5.2 >= 8.6.0, < 8.6.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | Initial Analysis | [email protected] |
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |