CVE-2026-29198
critical
CVSS v3
9.8
CVSS v2
—
VIR risk
9.8
Description
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: support@hackerone.com — https://github.com/RocketChat/Rocket.Chat/pull/39492
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| rocket.chat | rocket.chat | {"endExcluding":"7.10.9"} | 7.10.9 |
| rocket.chat | rocket.chat | 8.3.0 | |
References
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.