No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc0:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc1:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc2:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc3:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:8.3.0:rc4:*:*:*:*:*:* |
Tue, 28 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NoSQL Injection via OAuth App Enables Account Takeover in Rocket.Chat |
Mon, 27 Apr 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rocket.chat
Rocket.chat rocket.chat |
|
| Vendors & Products |
Rocket.chat
Rocket.chat rocket.chat |
Thu, 23 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Thu, 23 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-04-23T17:41:50.981Z
Reserved: 2026-03-04T15:00:09.266Z
Link: CVE-2026-29198
Updated: 2026-04-23T17:41:45.450Z
Status : Analyzed
Published: 2026-04-23T00:16:45.060
Modified: 2026-05-13T20:39:44.683
Link: CVE-2026-29198
No data.
OpenCVE Enrichment
Updated: 2026-04-28T15:15:34Z