{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "7.10.9"
              },
              {
                "introduced": "7.11.0"
              },
              {
                "fixed": "7.11.6"
              },
              {
                "introduced": "7.12.0"
              },
              {
                "fixed": "7.12.6"
              },
              {
                "introduced": "7.13.0"
              },
              {
                "fixed": "7.13.5"
              },
              {
                "introduced": "8.0.0"
              },
              {
                "fixed": "8.0.3"
              },
              {
                "introduced": "8.1.0"
              },
              {
                "fixed": "8.1.2"
              },
              {
                "introduced": "8.2.0"
              },
              {
                "fixed": "8.2.1"
              }
            ],
            "source": "CPE_RANGE"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "d439937001921056bbf876a3ead537ac84220d39"
            },
            {
              "introduced": "8d69961505afd986e64db5c7a332a65074a1ac4a"
            },
            {
              "fixed": "733a560c88c7236f159a951db554897736a04f9d"
            },
            {
              "introduced": "05f9767358c446a93fabf21d8e77f884ac775c0a"
            },
            {
              "fixed": "805f34877bcd00273dd7303520343d6a3bcb3f47"
            },
            {
              "introduced": "98c9d579501d877c263fe0a1db3cb69d0b52bf92"
            },
            {
              "fixed": "4fc3dcb05bc6ba55483ed8a199b82e477ce6beb0"
            },
            {
              "introduced": "9e2e148b8d8c474b307c24d59f8592a172f017f5"
            },
            {
              "fixed": "2d4d0059b1da34d240e96658b0886cb6ca47f150"
            },
            {
              "introduced": "2ca98764a077deb7efb710ff1d8f78c5c3e4c4a3"
            },
            {
              "fixed": "b57846f3b62824f060a9a80ad62c682859d62a6b"
            },
            {
              "introduced": "f2a05ceed2086266fa3e36cf575c1794f68f00ab"
            },
            {
              "fixed": "5e92280a47a2424b2aa30c39aa2e1ebe966f18ac"
            }
          ],
          "repo": "https://github.com/rocketchat/rocket.chat",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "hackerone",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29198.json"
  },
  "details": "In Rocket.Chat \u003c8.3.0, \u003c8.2.1, \u003c8.1.2, \u003c8.0.3, \u003c7.13.5, \u003c7.12.6, \u003c7.11.6, and \u003c7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.",
  "id": "CVE-2026-29198",
  "modified": "2026-07-15T01:49:01.034280613Z",
  "published": "2026-04-22T23:30:15.355Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/3564655"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29198.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29198"
    },
    {
      "type": "FIX",
      "url": "https://github.com/RocketChat/Rocket.Chat/pull/39492"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}