Detects Rocket.Chat instances affected by CVE-2026-30831 where the enterprise DDP Streamer accepts username/password login without enforcing 2FA or checking user-active status. Attackers can bypass two-factor authentication entirely via the DDP WebSocket endpoint.
Is your app exploitable through CVE-2026-30831?
Scan your domain free