Security Advisory

CVE-2026-22560

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-10 17:00:11
Last updated 2026-04-14 19:04:32
Assigner hackerone
State PUBLISHED

Description

An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.