Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rocket.chat
Rocket.chat rocket.chat |
|
| CPEs | cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.2.0:rc0:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.2.0:rc1:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.2.0:rc2:*:*:*:*:*:* |
|
| Vendors & Products |
Rocket.chat
Rocket.chat rocket.chat |
|
| Metrics |
cvssV3_1
|
Mon, 09 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rocketchat
Rocketchat rocket.chat |
|
| Vendors & Products |
Rocketchat
Rocketchat rocket.chat |
Fri, 06 Mar 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in Rocket.Chat's account service used in the ddp-streamer micro service that allows unauthenticated attackers to manipulate MongoDB queries during authentication. The vulnerability is located in the username-based login flow where user-supplied input is directly embedded into a MongoDB query selector without validation. An attacker can inject MongoDB operator expressions (e.g., { $regex: '.*' }) in place of a username string, causing the database query to match unintended user records. This issue has been patched in versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0. | |
| Title | Rocket.Chat: NoSQL injection in the EE ddp-streamer-service | |
| Weaknesses | CWE-943 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T14:56:03.564Z
Reserved: 2026-03-05T21:06:44.606Z
Link: CVE-2026-30833
Updated: 2026-03-09T14:55:59.509Z
Status : Analyzed
Published: 2026-03-06T18:16:22.013
Modified: 2026-03-13T18:46:27.120
Link: CVE-2026-30833
No data.
OpenCVE Enrichment
Updated: 2026-04-16T11:30:15Z