CVE-2026-45689 - Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO
CVE ID :CVE-2026-45689 Published : June 24, 2026, 8:57 p.m. | 4 hours, 13 minutes ago Description :Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker...