Unauthorized Access in Rocket.Chat API for OAuth Application Details
CVE-2026-23477
7.7HIGH
What is CVE-2026-23477?
In Rocket.Chat, a popular open-source communications platform, an API endpoint is accessible to any authenticated user, irrespective of their assigned role or permissions. This permits unauthorized exposure of sensitive OAuth application details, including client_id and client_secret for applications, if the user possesses the application ID. The issue has been resolved in version 6.12.0.
Affected Version(s)
Rocket.Chat < 6.12.0
