Security Advisory

CVE-2026-58066

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-30 06:03:45
Last updated 2026-07-31 03:55:47
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.