CVE-2026-29198

CRITICAL

Rocket.Chat <8.3.0 NoSQL Injection via OAuth App Configuration

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-29198. PoCs published by hieuminhnv.

AI-analyzed exploit summary This repository contains a functional Python-based PoC for CVE-2026-29198, a NoSQL injection vulnerability in Rocket.Chat's OAuth2 implementation. The exploit demonstrates authentication bypass by injecting NoSQL operators into the access_token parameter, allowing unauthenticated access to user data and potential privilege escalation.

Description

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.

Exploits (1)

github WORKING POC 1 stars
by hieuminhnv · pythonpoc
https://github.com/hieuminhnv/CVE-2026-29198-POC

This repository contains a functional Python-based PoC for CVE-2026-29198, a NoSQL injection vulnerability in Rocket.Chat's OAuth2 implementation. The exploit demonstrates authentication bypass by injecting NoSQL operators into the access_token parameter, allowing unauthenticated access to user data and potential privilege escalation.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, <7.10.9
No auth needed
Prerequisites: Active OAuth tokens in the database · Network access to the Rocket.Chat instance
devstral-2 · analyzed Jun 03, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0031
EPSS Percentile 22.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (9)
rocket.chat/rocket.chat 8.3.0 rc0 (5 CPE variants)
rocket.chat/rocket.chat < 7.10.9
Rocket.Chat/Rocket.Chat 7.10.9
Rocket.Chat/Rocket.Chat 7.11.6
Rocket.Chat/Rocket.Chat 7.12.6
Rocket.Chat/Rocket.Chat 7.13.5
Rocket.Chat/Rocket.Chat 8.0.3
Rocket.Chat/Rocket.Chat 8.2.1
Rocket.Chat/Rocket.Chat 8.3.0
Published Apr 23, 2026
Tracked Since Apr 23, 2026