cvesecurityvulnerability
CVE-2026-72918: Rocket.Chat WebSocket Lets Any Authenticated User Inject Fake Messages Into Other Users' Chats
Rocket.Chat's stream-notify-user WebSocket stream does not verify notification senders, so any authenticated user can inject ephemeral fake messages into another user's open chat. Fixed in 7.10.14 and 8.x releases.