9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbitrary user by sending a single HTTP POST with MongoDB query operators to /oauth/token. The Rocket.Chat OAuth2 server does not validate that grant parameters are strings before forwarding them to findOne({...}) against the oauth_apps and oauth_access_tokens collections, so an attacker substitutes {"$ne": null} for client_id, client_secret, and refresh_token and receives a freshly minted {access_token, refresh_token} pair bound to whichever user's refresh token Mongo returned first. The resulting access token is a first-class bearer credential against the full /api/v1/* surface as that user. By iterating with $nin / $regex operators the attacker walks the entire oauth_access_tokens collection, collecting one fresh access token per user per request. If any matched token belongs to an admin, the stolen bearer gives full admin API access (including Apps-Engine app installation, i.e. server-side code execution). No account, credentials, userId, or prior interaction with the instance are required. This vulnerability is fixed in 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11.
AI Analysis
Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO
Basic Information
ID
CVE-2026-45689
Source
GitHub_M
Published
Jun 24, 2026 at 20:57
Affected Product
Vendor
RocketChat
Product
Rocket.Chat
Version
>= 8.5.0-rc.0, < 8.5.0
Affected Versions
RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.0
RocketChat Rocket.Chat >= 8.4.0-rc.0, < 8.4.1
RocketChat Rocket.Chat >= 8.3.0-rc.0, < 8.3.3
RocketChat Rocket.Chat >= 8.2.0-rc.0, < 8.2.3
RocketChat Rocket.Chat >= 8.1.0-rc.0, < 8.1.4
RocketChat Rocket.Chat >= 8.0.0-rc.0, < 8.0.5
RocketChat Rocket.Chat >= 7.11.0-rc.0, < 7.13.7
RocketChat Rocket.Chat < 7.10.11
RocketChat Rocket.Chat >= 8.4.0-rc.0, < 8.4.1
RocketChat Rocket.Chat >= 8.3.0-rc.0, < 8.3.3
RocketChat Rocket.Chat >= 8.2.0-rc.0, < 8.2.3
RocketChat Rocket.Chat >= 8.1.0-rc.0, < 8.1.4
RocketChat Rocket.Chat >= 8.0.0-rc.0, < 8.0.5
RocketChat Rocket.Chat >= 7.11.0-rc.0, < 7.13.7
RocketChat Rocket.Chat < 7.10.11
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
RocketChat
Product
Rocket.Chat
Version
<= 8.5.0-rc.0, < 8.5.0, <= 8.4.0-rc.0, < 8.4.1, <= 8.3.0-rc.0, < 8.3.3, <= 8.2.0-rc.0, < 8.2.3, <= 8.1.0-rc.0, < 8.1.4, <= 8.0.0-rc.0, < 8.0.5, <= 7.11.0-rc.0, < 7.13.7, < 7.10.11