Home

Description

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.

PUBLISHED Reserved 2026-03-04 | Published 2026-04-22 | Updated 2026-04-23 | Assigner hackerone

Product status

Default status
affected

8.3.0 (semver) before 8.3.0
unaffected

8.2.1 (semver) before 8.2.1
unaffected

8.0.3 (semver) before 8.0.3
unaffected

7.13.5 (semver) before 7.13.5
unaffected

7.12.6 (semver) before 7.12.6
unaffected

7.11.6 (semver) before 7.11.6
unaffected

7.10.9 (semver) before 7.10.9
unaffected

References

hackerone.com/reports/3564655

github.com/RocketChat/Rocket.Chat/pull/39492

cve.org (CVE-2026-29198)

nvd.nist.gov (CVE-2026-29198)

Download JSON