NoSQL Injection Vulnerability in Rocket.Chat's Account Service
CVE-2026-30833

6.9MEDIUM

Key Information:

Vendor

Rocketchat

Vendor
CVE Published:
6 March 2026

What is CVE-2026-30833?

Rocket.Chat, a well-known open-source communication platform, has a vulnerability in its account service prior to multiple specified versions. This NoSQL injection vulnerability affects the ddp-streamer microservice, enabling unauthenticated attackers to exploit weak input validation in the username login process. By injecting MongoDB operator expressions into the query, adversaries can manipulate database queries to access unintended user records, posing significant security risks. Users are advised to upgrade to the patched versions to mitigate potential threats.

Affected Version(s)

Rocket.Chat < 7.10.8 < 7.10.8

Rocket.Chat < 7.11.5 < 7.11.5

Rocket.Chat < 7.12.5 < 7.12.5

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.