CVE-2026-22560

Publication date

2026-04-10 17:00:11

Family

hackerone

State

PUBLISHED

Description

An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.