All verified exploits

CVE-2026-30831 DDP Streamer Authentication Bypass

Deterministic critical Rocket.Chat Added cve-verified-cve-2026-30831

Detects Rocket.Chat instances affected by CVE-2026-30831 where the enterprise DDP Streamer accepts username/password login without enforcing 2FA or checking user-active status. Attackers can bypass two-factor authentication entirely via the DDP WebSocket endpoint.

Related Rocket.Chat exploits

Is your app exploitable through CVE-2026-30831?

Scan your domain free