A vulnerability identified as problematic has been detected in RocketChat Rocket.Chat up to 8.6.0. This impacts an unknown function of the component Stream-Notify-User Stream. The manipulation leads to improper privilege management.

This vulnerability is referenced as CVE-2026-72918. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.