PT-2026-31988 · Rocket.Chat · Rocket.Chat

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-22560

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-22560

Affected Products

Rocket.Chat