NoSQL Injection Vulnerability in Rocket.Chat's Account Service
CVE-2026-30833
6.9MEDIUM
What is CVE-2026-30833?
Rocket.Chat, a well-known open-source communication platform, has a vulnerability in its account service prior to multiple specified versions. This NoSQL injection vulnerability affects the ddp-streamer microservice, enabling unauthenticated attackers to exploit weak input validation in the username login process. By injecting MongoDB operator expressions into the query, adversaries can manipulate database queries to access unintended user records, posing significant security risks. Users are advised to upgrade to the patched versions to mitigate potential threats.
Affected Version(s)
Rocket.Chat < 7.10.8 < 7.10.8
Rocket.Chat < 7.11.5 < 7.11.5
Rocket.Chat < 7.12.5 < 7.12.5
