Answer in brief
CVE-2026-75575 records a Medium severity (CVSS 5.3) vulnerability in Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method. The current sources do not mark it as known exploited. The current feed maps RocketChat/Rocket.Chat (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps RocketChat/Rocket.Chat (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| RocketChat/Rocket.Chatgeneric | >=0 <7.10.15 || >=8.0.0 <8.1.8 || >=8.2.0 <8.2.8 || >=8.3.0 <8.3.8 || >=8.4.0 <8.4.6 || >=8.5.0 <8.5.3 || >=8.6.0 <8.6.2 || >=8.7.0 <8.7.2 || >=8.8.0-rc.0 <8.8.0 | 7.10.15, 8.1.8, 8.2.8, 8.3.8, 8.4.6, 8.5.3, 8.6.2, 8.7.2, 8.8.0 |
Published upstream
Aug 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 25, 2026
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAnon/sendForgotPasswordEmail, and it triggers a password reset message for any address that matches an account. With no DDPRateLimiter rule registered for it, a caller can drive an unbounded volume of reset mail at a chosen address from the deployment's own mail sender, and can probe addresses at scale: the method answers true for an address with no account and for a successful send, but false when the address belongs to an account that authenticates through an external provider and Accounts_AllowPasswordChangeForOAuthUsers is off, so repeated calls distinguish that class of account. Later versions register a rule permitting ten calls per minute per client address.
Quoted source text, attributed separately from HOL analysis.