Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN876
_____________________________________________________________________

DATE                : 09/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Rocket.Chat versions prior to
                     8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7,
                                       8.0.8, 7.10.14.
 
=====================================================================
https://github.com/advisories/GHSA-f3wj-pr2w-q3fm
https://github.com/RocketChat/Rocket.Chat/issues/41647
https://github.com/RocketChat/Rocket.Chat/issues/41646
_____________________________________________________________________


Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5... 
Critical severity Unreviewed Published on Jul 30 to the GitHub
Advisory Database • Updated on Jul 30

Package
No package listed— Suggest a package

Affected versions
Unknown

Patched versions
Unknown


Description

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5,
8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but
did not bind the validated signature to samlp:Response / saml:Assertion.
An attacker could submit a wrapped document carrying forged identity
attributes alongside any valid signature made by the trusted IdP
certificate, and log in as an arbitrary user.
References

    https://nvd.nist.gov/vuln/detail/CVE-2026-58066
    RocketChat/Rocket.Chat#41233
    https://hackerone.com/reports/3827674


Severity
Critical
9.8/ 10

CVSS v3 base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS score
0.234% (14th percentile)

Weaknesses
Weakness CWE-287

CVE ID
CVE-2026-58066

GHSA ID
GHSA-f3wj-pr2w-q3fm

Source code
No known source code 

_____________________________________________________________________

[Security] SAML LogoutResponse POST binding has no signature validation
- force-logout any user (sibling of CVE-2026-58066)
#41647

Description
@leanworld7-netizen
leanworld7-netizen

opened on Jul 31

Summary

The SAML LogoutResponse POST binding path in Rocket.Chat has ZERO
signature validation, enabling an attacker to forge logout responses
and force-logout arbitrary users. This is a sibling vulnerability to
CVE-2026-58066 (SAML XSW on Response path) but worse - the
LogoutResponse POST path has no signature validation at all.


Affected Code

File: apps/meteor/server/lib/saml/lib/parsers/Response.ts, method _checkLogoutResponse (lines 201-216)


Vulnerability Details

When a SAML POST message is received, Response.ts validate() first
looks for Response elements (L67). If none are found, it falls through
to _checkLogoutResponse (L69).

The _checkLogoutResponse method:

    Finds LogoutResponse elements via getElementsByTagNameNS (L202)
    Validates the SAML status (L208-211)
    Returns success: callback(null, null, true) (L215)

MISSING security checks (present on Response path but absent here):

    No document root check - The Response path checks
response !== doc.documentElement at L77-78 (the CVE-2026-58066 fix).
The LogoutResponse path has no such check, making it vulnerable to
XSW wrapping attacks.

    No signature validation - The Response path calls
validateResponseSignature (L312) and validateAssertionSignature (L316),
which use validateSignatureChildren (L320) with getElementId binding
(L344). The LogoutResponse path performs NO signature validation at all.

    No element ID binding - The getElementId method (L347) binds
signatures to element IDs to prevent signature replay. This is never
called for LogoutResponse.

The @ToDo: Check if this situation is still used comment at L214
confirms the development team is unsure whether this code path is
active.


Comparison: LogoutResponse.ts vs _checkLogoutResponse

The separate LogoutResponse.ts class (used for REDIRECT binding) DOES
verify signatures via verifySignature(envelope). However, the
POST-based _checkLogoutResponse method in Response.ts has no equivalent
signature check.


Attack Scenario

    Attacker crafts a SAML LogoutResponse POST message with valid status
    Sends it to Rocket.Chat's SAML ACS endpoint
    _checkLogoutResponse accepts the forged response without signature
verification
    Target user is logged out


Impact

    Force-logout any user - attacker can forge logout responses for any
user
    Session fixation - combined with re-login, could enable session
hijacking
    Denial of Service - mass logout of all users
    XSW on logout path - without root check, attacker can wrap the
LogoutResponse in an outer element and inject a forged response


Severity

HIGH (CVSS 7.5) - Authentication bypass via forged logout response
Relationship to CVE-2026-58066

CVE-2026-58066 fixed XSW on the SAML Response path by adding document
root check and signature-to-element-ID binding. The fix did NOT cover
the LogoutResponse POST path, which remains completely
unprotected - not just from XSW, but from any signature validation at
all.


Recommendation

    Add document root check to _checkLogoutResponse:
verify logoutResponse[0] === doc.documentElement
    Add signature validation to _checkLogoutResponse using the
same validateSignatureChildren + getElementId pattern
    Remove the @ToDo comment and confirm whether this path is
still needed


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




