CVE-2026-30831

Source
https://cve.org/CVERecord?id=CVE-2026-30831
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-30831.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-30831
Aliases
  • GHSA-7qr6-q62g-hm63
Published
2026-03-06T17:40:27.824Z
Modified
2026-04-10T05:41:53.502519Z
Severity
  • 8.0 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer
Details

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer service. The Account.login method exposed through the DDP Streamer does not enforce Two-Factor Authentication (2FA) or validate user account status (deactivated users can still login), despite these checks being mandatory in the standard Meteor login flow. This issue has been patched in versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30831.json",
    "cwe_ids": [
        "CWE-287",
        "CWE-304"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/rocketchat/rocket.chat

Affected ranges

Type
GIT
Repo
https://github.com/rocketchat/rocket.chat
Events

Affected versions

8.*
8.1.0
8.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-30831.json"