MEDIUM

CVE-2026-49278

2026-06-24 CVSS v3.1
CVSS
6.7

Description

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-information-by-id-1, token is returned in the response. It looks like there's no use case for the token to be present in the response and it would be a good security practice to remove it altogether. This vulnerability is fixed in 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12.

Summary dbcve.org

Rocket.Chat's visitors.info API endpoint incorrectly returns a visitor token in the response. This sensitive token should not be exposed as it could be used for visitor impersonation or session hijacking. The fix involves removing the token field from the API response.

Mitigation

Upgrade Rocket.Chat to version 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, or 7.10.12 or later, which removes the token from the visitors.info endpoint response.

Weakness (CWE)

CWE-285 Improper Authorization

EPSS Score

0.41%
Probability of exploitation in next 30 days
35.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE