CVE-2026-56845: Rocket.chat

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.

Affected products

  • Rocket.chat Rocket.chat: before 8.2.0 (fixed in 8.2.0); before 8.1.1 (fixed in 8.1.1); before 8.0.2 (fixed in 8.0.2); before 7.13.4 (fixed in 7.13.4); before 7.12.5 (fixed in 7.12.5); before 7.11.5 (fixed in 7.11.5); …

Published 2026-08-04. Last modified 2026-09-09.