CVE-2026-29198

EUVD-2026-25129
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
rocket.chatrocket.chat
𝑥
< 7.10.9
rocket.chatrocket.chat
7.11.0 ≤
𝑥
< 7.11.6
rocket.chatrocket.chat
7.12.0 ≤
𝑥
< 7.12.6
rocket.chatrocket.chat
7.13.0 ≤
𝑥
< 7.13.5
rocket.chatrocket.chat
8.0.0 ≤
𝑥
< 8.0.3
rocket.chatrocket.chat
8.1.0 ≤
𝑥
< 8.1.2
rocket.chatrocket.chat
8.2.0 ≤
𝑥
< 8.2.1
rocket.chatrocket.chat
8.3.0:rc0
rocket.chatrocket.chat
8.3.0:rc1
rocket.chatrocket.chat
8.3.0:rc2
rocket.chatrocket.chat
8.3.0:rc3
rocket.chatrocket.chat
8.3.0:rc4
𝑥
= Vulnerable software versions