In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NoSQL Injection via OAuth App Enables Account Takeover in Rocket.Chat |
Mon, 27 Apr 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rocket.chat
Rocket.chat rocket.chat |
|
| Vendors & Products |
Rocket.chat
Rocket.chat rocket.chat |
Thu, 23 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Thu, 23 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured. | |
| References |
|
Status: PUBLISHED
Assigner: hackerone
Published: 2026-04-22T23:30:15.355Z
Updated: 2026-04-23T17:41:50.981Z
Reserved: 2026-03-04T15:00:09.266Z
Link: CVE-2026-29198
Updated: 2026-04-23T17:41:45.450Z
Status : Awaiting Analysis
Published: 2026-04-23T00:16:45.060
Modified: 2026-04-24T14:50:56.203
Link: CVE-2026-29198
No data.
ReportizFlow