# CVE-2026-45689

## Summary

- **CVE ID:** CVE-2026-45689
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-943
- **Published:** Jun 24, 2026
- **Last Modified:** Jun 26, 2026

## Description

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbitrary user by sending a single HTTP POST with MongoDB query operators to /oauth/token. The Rocket.Chat OAuth2 server does not validate that grant parameters are strings before forwarding them to findOne({...}) against the oauth_apps and oauth_access_tokens collections, so an attacker substitutes {"$ne": null} for client_id, client_secret, and refresh_token and receives a freshly minted {access_token, refresh_token} pair bound to whichever user's refresh token Mongo returned first. The resulting access token is a first-class bearer credential against the full /api/v1/* surface as that user. By iterating with $nin / $regex operators the attacker walks the entire oauth_access_tokens collection, collecting one fresh access token per user per request. If any matched token belongs to an admin, the stolen bearer gives full admin API access (including Apps-Engine app installation, i.e. server-side code execution). No account, credentials, userId, or prior interaction with the instance are required. This vulnerability is fixed in 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11.

## Affected Products

- RocketChat — Rocket.Chat (>= 8.5.0-rc.0, < 8.5.0)
- RocketChat — Rocket.Chat (>= 8.4.0-rc.0, < 8.4.1)
- RocketChat — Rocket.Chat (>= 8.3.0-rc.0, < 8.3.3)
- RocketChat — Rocket.Chat (>= 8.2.0-rc.0, < 8.2.3)
- RocketChat — Rocket.Chat (>= 8.1.0-rc.0, < 8.1.4)
- RocketChat — Rocket.Chat (>= 8.0.0-rc.0, < 8.0.5)
- RocketChat — Rocket.Chat (>= 7.11.0-rc.0, < 7.13.7)
- RocketChat — Rocket.Chat (< 7.10.11)

## References

- [CNA](https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-8p25-fm45-pjrw)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.53%
- **EPSS Percentile:** 42.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._