CVE-2026-29198
EUVD-2026-2512923.04.2026, 00:16
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| rocket.chat | rocket.chat | 𝑥 < 7.10.9 |
| rocket.chat | rocket.chat | 7.11.0 ≤ 𝑥 < 7.11.6 |
| rocket.chat | rocket.chat | 7.12.0 ≤ 𝑥 < 7.12.6 |
| rocket.chat | rocket.chat | 7.13.0 ≤ 𝑥 < 7.13.5 |
| rocket.chat | rocket.chat | 8.0.0 ≤ 𝑥 < 8.0.3 |
| rocket.chat | rocket.chat | 8.1.0 ≤ 𝑥 < 8.1.2 |
| rocket.chat | rocket.chat | 8.2.0 ≤ 𝑥 < 8.2.1 |
| rocket.chat | rocket.chat | 8.3.0:rc0 |
| rocket.chat | rocket.chat | 8.3.0:rc1 |
| rocket.chat | rocket.chat | 8.3.0:rc2 |
| rocket.chat | rocket.chat | 8.3.0:rc3 |
| rocket.chat | rocket.chat | 8.3.0:rc4 |
𝑥
= Vulnerable software versions