PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65645 Rocket.Chat CVE debrief

The CVE-2026-65645 vulnerability affects Rocket.Chat versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15. The Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters without schema validation, allowing a MongoDB operator object to be substituted for a string room-id or message-id. This could lead to disclosure of private thread parents and their full reply content to any low-privilege authenticated user. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Users and administrators of Rocket.Chat should review and apply vendor patches to mitigate this vulnerability.

Vendor
Rocket.Chat
Product
Unknown
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-09-03
Advisory published
2026-08-21
Advisory updated
2026-09-03

Who should care

Rocket.Chat users and administrators, security teams monitoring for potential exploitation of this vulnerability, and operators responsible for maintaining and securing Rocket.Chat deployments should be aware of this issue. They should review the vulnerability details and apply patches or mitigations as necessary to prevent exploitation. Additionally, security teams should monitor for suspicious activity related to thread and message access, and implement additional authentication and authorization checks for Meteor DDP methods where possible. Affected operators and platform administrators should prioritize patching and review compensating controls for exposed systems while remediation is scheduled and verified. Vulnerability management and security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. This may involve coordinating with Rocket.Chat support and monitoring for updates on patched versions and best practices for securing Meteor DDP methods. The limited information available suggests verifying affected scope, severity, and vendor guidance through official advisories or CVE records. Managed environment owners should confirm whether affected product deployments exist and assign an owner for follow-up. Compensating controls and monitoring should be reviewed for exposed systems while remediation is in progress. Asset inventory and source tracking may be necessary to ensure complete remediation. Rollback change windows may be required if patches cannot be immediately applied. The goal is to minimize exposure and prevent unauthorized access to sensitive information. By taking these steps, organizations can reduce the risk associated with CVE-2026-65645 and protect their Rocket.Chat deployments from potential exploitation. This requires coordination between operators, security teams, and vendors to ensure effective mitigation and remediation of the vulnerability. The vulnerability's impact on operational security and potential for data disclosure underscores the importance of prompt action and thorough remediation efforts. Therefore, it is crucial for all stakeholders to be aware of this vulnerability

Technical summary

The Meteor DDP methods getThreadsList and getThreadMessages in Rocket.Chat versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 accept rid / tmid as raw, untyped parameters without schema validation. This allows a MongoDB operator object to be substituted for a string room-id or message-id, potentially disclosing private thread parents and their full reply content to any low-privilege authenticated user.

Defensive priority

Authenticated users with low privileges may be able to exploit this vulnerability to disclose private thread parents and their full reply content.

Recommended defensive actions

  • Review and apply vendor patches for Rocket.Chat versions before 8.8.0
  • Implement additional authentication and authorization checks for Meteor DDP methods
  • Monitor for suspicious activity related to thread and message access
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE-2026-65645 record indicates Rocket.Chat versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 have an issue with Meteor DDP methods getThreadsList and getThreadMessages. These methods accept rid / tmid as raw, untyped parameters without schema validation, allowing a MongoDB operator object to be substituted for a string room-id or message-id. This could lead to disclosure of private thread parents and their full reply content to any low-privilege authenticated user. Evidence is based on limited CVE and NVD information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-65645 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-65645

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-65645 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65645

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.