CVE-2026-23477

Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth application, as long as the user knows its ID, including potentially sensitive fields such as client_id and client_secret. This vulnerability is fixed in 6.12.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:21

Type Values Removed Values Added
Summary
  • (es) Rocket.Chat es una plataforma de comunicaciones de código abierto, segura y totalmente personalizable. En las versiones de Rocket.Chat hasta la 6.12.0, el endpoint de la API GET /api/v1/oauth-apps.get está expuesto a cualquier usuario autenticado, independientemente de su rol o permisos. Este endpoint devuelve una aplicación OAuth, siempre que el usuario conozca su ID, incluyendo campos potencialmente sensibles como client_id y client_secret. Esta vulnerabilidad está corregida en la 6.12.0.

26 Jan 2026, 18:03

Type Values Removed Values Added
First Time Rocket.chat
Rocket.chat rocket.chat
CPE cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
References () https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-g4wm-fg3c-g4p2 - () https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-g4wm-fg3c-g4p2 - Exploit, Third Party Advisory

14 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 19:16

Updated : 2026-06-17 10:21


NVD link : CVE-2026-23477

Mitre link : CVE-2026-23477

CVE.ORG link : CVE-2026-23477


JSON object : View

Products Affected

rocket.chat

  • rocket.chat
CWE
CWE-269

Improper Privilege Management

CWE-862

Missing Authorization