---
id: CVE-2026-72919
title: >-
  Rocket.Chat is an open-source, secure, fully customizable communications
  platform
summary: >-
  Rocket.Chat is an open-source, secure, fully customizable communications
  platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and
  8.6.1, the channels.convertToTeam REST endpoint allows an authenticated
  registered user wi…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2026-08-10'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:50:00.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72919'
references:
  - url: >-
      https://github.com/RocketChat/Rocket.Chat/commit/175a19c4151f41910499ef37df54f58022276d12
    label: security-advisories@github.com
  - url: 'https://github.com/RocketChat/Rocket.Chat/pull/41206'
    label: security-advisories@github.com
  - url: >-
      https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-4mvx-9h2h-hmg3
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00325
epssPercentile: 0.22943
ingestedAt: '2026-09-09T21:22:45.526Z'
---

## Overview

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated registered user with the create-team permission to convert an unrelated public channel by supplying channelName instead of channelId because the edit-room permission is checked only for channelId. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
