Vulnerability Description
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth bearer or refresh tokens when a user is deactivated. A deactivated user can continue using an existing OAuth access token, and can also mint a fresh access token from an existing refresh token. This vulnerability is fixed in 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-49277?
CVE-2026-49277 is a documented vulnerability. Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth bearer or r...
How severe is CVE-2026-49277?
CVSS scoring is not yet available for CVE-2026-49277. Check NVD for updates.
Is there a patch for CVE-2026-49277?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.