CVE-2026-29198CRITICAL 9.8EPSS p22.3%

CVE-2026-29198CVE-2026-29198

Description

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.31% probability of exploitation · percentile 22.3% · 2026-06-18T12:00:27Z
Published2026-04-23
Last modified2026-05-13

Underlying weaknesses· 1

CWE-89

References

  1. https://github.com/RocketChat/Rocket.Chat/pull/39492
  2. https://hackerone.com/reports/3564655

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-890%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-28514
CVE
CVE-2026-30831
CVE
CVE-2026-32995
CVE
CVE-2025-39366
CVE
CVE-2026-29204
CVE
CVE-2026-33265
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.