Detects Rocket.Chat instances affected by CVE-2026-28514 where the enterprise DDP Streamer's account service calls an async password validation function without await. The returned Promise is always truthy, allowing any password to authenticate as any user.
Is your app exploitable through CVE-2026-28514?
Scan your domain free