A vulnerability marked as critical has been reported in RocketChat Rocket.Chat up to 8.6.0. Affected by this vulnerability is an unknown functionality of the component channels.convertToTeam. This manipulation of the argument channelName/channelId causes permission issues.
This vulnerability is tracked as CVE-2026-72919. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.