---
id: CVE-2026-72918
title: >-
  Rocket.Chat is an open-source, secure, fully customizable communications
  platform
summary: >-
  Rocket.Chat is an open-source, secure, fully customizable communications
  platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and
  8.6.1, the stream-notify-user stream in the WebSocket protocol allows an
  authenticated use…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-862
published: '2026-08-10'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:50:00.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72918'
references:
  - url: >-
      https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-27jx-236m-3f5j
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00225
epssPercentile: 0.1184
ingestedAt: '2026-09-09T21:22:45.526Z'
---

## Overview

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated user to write arbitrary notification bodies because the sender is not checked, and the client-side UI can create an ephemeral fake message in another user's currently open chat. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
