Home

Description

In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing authenticated users without the proper permissions to read apps-engine logs.

PUBLISHED Reserved 2026-03-04 | Published 2026-04-23 | Updated 2026-04-24 | Assigner hackerone

Problem types

CWE-284 Improper Access Control - Generic

Product status

Default status
unaffected

8.4.0 (semver) before 8.4.0
affected

8.3.2 (semver) before 8.3.2
affected

8.2.2 (semver) before 8.2.2
affected

8.1.3 (semver) before 8.1.3
affected

8.0.4 (semver) before 8.0.4
affected

7.13.6 (semver) before 7.13.6
affected

7.12.7 (semver) before 7.12.7
affected

7.11.7 (semver) before 7.11.7
affected

7.10.10 (semver) before 7.10.10
affected

References

hackerone.com/reports/3589551

github.com/RocketChat/Rocket.Chat/pull/40125

cve.org (CVE-2026-29197)

nvd.nist.gov (CVE-2026-29197)

Download JSON