Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-45689 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbitrary user by sending a single HTTP POST with MongoDB query operators to /oauth/token. The Rocket.Chat OAuth2 server does not validate that grant parameters are strings before forwarding them to findOne({...}) against the oauth_apps and oauth_access_tokens collections, so an attacker substitutes {"$ne": null} for client_id, client_secret, and refresh_token and receives a freshly minted {access_token, refresh_token} pair bound to whichever user's refresh token Mongo returned first. The resulting access token is a first-class bearer credential against the full /api/v1/* surface as that user. By iterating with $nin / $regex operators the attacker walks the entire oauth_access_tokens collection, collecting one fresh access token per user per request. If any matched token belongs to an admin, the stolen bearer gives full admin API access (including Apps-Engine app installation, i.e. server-side code execution). No account, credentials, userId, or prior interaction with the instance are required. This vulnerability is fixed in 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-943Improper Neutralization of Special Elements in Data Query Logic[email protected]

Affected Products

ProductVersions
Rocket.Chat
< 8.5.0 (semver)
< 8.4.1 (semver)
< 8.3.3 (semver)
< 8.2.3 (semver)
< 8.1.4 (semver)

CPE

  • cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 8.5.0moderate effort
  • Upgrade: 8.4.1moderate effort
  • Upgrade: 8.3.3moderate effort
  • Upgrade: 8.2.3moderate effort
  • Upgrade: 8.1.4moderate effort
  • Upgrade: 8.0.5moderate effort
  • Upgrade: 7.13.7moderate effort
  • Upgrade: 7.10.11moderate effort

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-45689
NVD Published Date:
Jun 24, 2026
NVD Last Modified:
Jun 26, 2026
Source:
[email protected]
CVE-2026-45689 Details - Not Deferred