CVE-2026-22560: Rocket.chat
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.
Affected products
- Rocket.chat Rocket.chat: before 8.4.0 (fixed in 8.4.0)
Published 2026-04-10. Last modified 2026-06-17.