CVE-2026-23477

Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth application, as long as the user knows its ID, including potentially sensitive fields such as client_id and client_secret. This vulnerability is fixed in 6.12.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-14 19:16

Updated : 2026-01-26 18:03


NVD link : CVE-2026-23477

Mitre link : CVE-2026-23477

CVE.ORG link : CVE-2026-23477


JSON object : View

Products Affected

rocket.chat

  • rocket.chat
CWE
CWE-269

Improper Privilege Management

CWE-862

Missing Authorization