Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 13 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc0:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc1:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc2:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc3:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc4:*:*:*:*:*:* |
Tue, 28 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NoSQL Injection via OAuth App Enables Account Takeover in Rocket.Chat |
Mon, 27 Apr 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rocket.chat
Rocket.chat rocket.chat |
|
| Vendors & Products |
Rocket.chat
Rocket.chat rocket.chat |
Thu, 23 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Thu, 23 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured. | |
| References |
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-04-23T17:41:50.981Z
Reserved: 2026-03-04T15:00:09.266Z
Link: CVE-2026-29198
Updated: 2026-04-23T17:41:45.450Z
Status : Analyzed
Published: 2026-04-23T00:16:45.060
Modified: 2026-05-13T20:39:44.683
Link: CVE-2026-29198
No data.
OpenCVE Enrichment
Updated: 2026-04-28T15:15:34Z