vulns.co
/
GKData.io MCP

GitHub Security Lab · 2 min read

Rocket.Chat: authentication must await a completed verification decision

CVE-2026-28514 concerned asynchronous password verification in the enterprise account service. The authentication decision treated an unfinished validation object as success instead of using its eventual result. The researcher tested Rocket.Chat 7.13.2; the maintainer corroborates unauthorized access to available service methods, with possible account takeover depending on subsequent application behavior.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Editorial lesson: model authentication as a completed, explicit decision; pending, rejected, and failed validation must not imply success. Maintain regression coverage for asynchronous rejection and service-specific authentication equivalence. The maintainer remediation requires waiting for verification and recommends tooling to detect unhandled asynchronous results.

Before reading

  • Basic server-side authentication and authorization concepts

Context and limits

  • Requires the affected enterprise streaming/account-service deployment and an account with password authentication configured; the reported identity must be known or guessable. Do not generalize this to every Rocket.Chat installation or authentication mode.
  • The researcher describes broad takeover potential. The maintainer impact statement is narrower: access to available service methods, with takeover dependent on the application path. Neither source supplies a customer incident count.
  • Reported January 9, 2026; the researcher dates the initial 8.0.0 fix to January 12 and supported-version fixes to March 5. The maintainer advisory was published March 5; detailed research March 12. These are not resource version-release dates.
  • Maintainer-listed patched releases: 8.0.0, 7.13.3, 7.12.4, 7.11.4, 7.10.7, 7.9.8 and 7.8.6. No deployment remediation was verified.
  • The research page also covers CVE-2026-30833; this resource is confined to asynchronous authentication verification and does not summarize a combined attack.
  • Byline: Peter Stöckli. Discovery used GitHub Security Lab Taskflow Agent, manually verified by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial.

Sources and provenance

  1. GHSL-2026-004_GHSL-2026-005: Authentication bypass in Rocket.Chat GitHub Security Lab · reviewed 2026-10-03
  2. Users can login with any password via the EE ddp-streamer-service Rocket.Chat · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software