CVE-2026-22560: Rocket.chat

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.

Affected products

Published 2026-04-10. Last modified 2026-06-17.