Impact
In Rocket.Chat versions prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint endpoint requires authentication but performs no authorization check. Any authenticated user can call the endpoint with the payload {"setDeploymentAs":"new-workspace"}, which permanently deregisters the workspace from Rocket.Chat Cloud, wipes all cloud credentials, removes the workspace license, and disables push notifications for all users. This constitutes a privilege escalation and availability impact, consistent with CWE‑862.
Affected Systems
Affected users are those running Rocket.Chat from the open‑source, secure communications platform, specifically versions 8.5.0 or earlier, 8.4.3 or earlier, 8.3.5 or earlier, 8.2.5 or earlier, 8.1.5 or earlier, 8.0.6 or earlier, and 7.10.12 or earlier. The fix is released in the corresponding newer patch releases noted above.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. Although the EPSS score is not available, the vulnerability is known to be exploitable by any authenticated user, so internal users could trigger it at will. The issue is not listed in CISA KEV, suggesting that there is no confirmed widespread exploitation yet, but the lack of authorization makes it easy to abuse if an attacker gains legitimate credentials or compromises an account.
OpenCVE Enrichment