CVE-2026-23477

Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth application, as long as the user knows its ID, including potentially sensitive fields such as client_id and client_secret. This vulnerability is fixed in 6.12.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*

History

26 Jan 2026, 18:03

Type Values Removed Values Added
First Time Rocket.chat
Rocket.chat rocket.chat
CPE cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
References () https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-g4wm-fg3c-g4p2 - () https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-g4wm-fg3c-g4p2 - Exploit, Third Party Advisory

14 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 19:16

Updated : 2026-01-26 18:03


NVD link : CVE-2026-23477

Mitre link : CVE-2026-23477

CVE.ORG link : CVE-2026-23477


JSON object : View

Products Affected

rocket.chat

  • rocket.chat
CWE
CWE-269

Improper Privilege Management

CWE-862

Missing Authorization