CVE-2026-29198
CRITICALRocket.Chat <8.3.0 NoSQL Injection via OAuth App Configuration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-29198. PoCs published by hieuminhnv.
AI-analyzed exploit summary This repository contains a functional Python-based PoC for CVE-2026-29198, a NoSQL injection vulnerability in Rocket.Chat's OAuth2 implementation. The exploit demonstrates authentication bypass by injecting NoSQL operators into the access_token parameter, allowing unauthenticated access to user data and potential privilege escalation.
Description
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.
Exploits (1)
This repository contains a functional Python-based PoC for CVE-2026-29198, a NoSQL injection vulnerability in Rocket.Chat's OAuth2 implementation. The exploit demonstrates authentication bypass by injecting NoSQL operators into the access_token parameter, allowing unauthenticated access to user data and potential privilege escalation.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H