Rocket.Chat disclosed and patched critical authentication flaws in its Enterprise DDP Streamer (ddp-streamer-service) that can enable account takeover and policy bypass. CVE-2026-28514 allows an attacker to authenticate as any user with a password set using an arbitrary password due to an implementation bug in async password validation (a missing await causes a truthy Promise to be treated as successful validation), making exploitation feasible when usernames are known or guessable.
A second issue, CVE-2026-30831, affects the same Enterprise DDP Streamer login path where Account.login fails to enforce 2FA and does not validate account status, allowing 2FA bypass and permitting deactivated users to log in. Rocket.Chat reports fixes across multiple release trains, including patched versions 7.8.6/7.9.8/7.10.7/7.11.4/7.12.4/7.13.3/8.0.0 for CVE-2026-28514 and 7.10.8/7.11.5/7.12.5/7.13.4/8.0.2/8.1.1/8.2.0 for CVE-2026-30831; organizations running affected Enterprise DDP Streamer components should prioritize upgrades to the fixed builds to prevent unauthorized access paths.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Rocket.Chat disclosed vulnerabilities in the enterprise DDP Streamer login path that failed to enforce two-factor authentication and did not validate whether accounts were deactivated. The issues were fixed in versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0.
Rocket.Chat disclosed a critical authentication bypass in its account service used by the enterprise ddp-streamer microservice. The flaw, caused by a missing await in asynchronous password validation, allowed login as any user with an arbitrary password in affected versions before patched releases 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.