CVE-2026-65645 | Rocket.Chat up to 8.7.x Meteor DDP getThreadsList/getThreadMessages rid/tmid improper authorization (EUVD-2026-63805)
A vulnerability identified as problematic has been detected in Rocket.Chat up to 8.7.x. Impacted is the function getThreadsList/getThreadMessages of the component Meteor DDP. The manipulation of the argument rid/tmid leads to improper authorization.
This vulnerability is referenced as CVE-2026-65645. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More