Missing Authentication for Critical Function in Rocket.Chat - CVE-2026-45677
Published: May 14, 2026
Rocket.Chat
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper authentication in SAML logout request processing when handling inbound LogoutRequest messages at the SP logout endpoint. A remote attacker can submit a valid-looking unsigned LogoutRequest for a target user to cause a denial of service.
Exploitation requires knowledge of the target user's SAML NameID.