<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T21:26:16.316386+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-32995</id>
    <title>CVE-2026-32995</title>
    <updated>2026-10-06T21:26:16.334605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocket.Chat</p>
<p>The Rocket.Chat DDP method autoTranslate.translateMessage in versions &lt;8.5.0, &lt;8.4.2, &lt;8.3.4, &lt;8.2.4, &lt;8.1.5, &lt;8.0.5, &lt;7.13.8, and &lt;7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor.userId() or verifying room membership. Any authenticated DDP user can read the content of any message by ID from any room (private channels, DMs, E2EE rooms) by calling this method.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-32995"/>
  </entry>
</feed>
