CVE-2026-29197

Source
https://cve.org/CVERecord?id=CVE-2026-29197
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29197.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-29197
Published
2026-04-23T23:19:40.722Z
Modified
2026-08-12T03:51:12.572376869Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing authenticated users without the proper permissions to read apps-engine logs.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "cna_assigner": "hackerone",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29197.json"
}
References

Affected packages

Git / github.com/rocketchat/rocket.chat

Affected ranges

Type
GIT
Repo
https://github.com/rocketchat/rocket.chat
Events
Database specific
Show details
{
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "7.10.0"
        },
        {
            "fixed": "7.10.10"
        },
        {
            "introduced": "7.11.0"
        },
        {
            "fixed": "7.11.7"
        },
        {
            "introduced": "7.12.0"
        },
        {
            "fixed": "7.12.7"
        },
        {
            "introduced": "7.13.0"
        },
        {
            "fixed": "7.13.6"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.0.4"
        },
        {
            "introduced": "8.1.0"
        },
        {
            "fixed": "8.1.3"
        },
        {
            "introduced": "8.2.0"
        },
        {
            "fixed": "8.2.2"
        },
        {
            "introduced": "8.3.0"
        },
        {
            "fixed": "8.3.2"
        }
    ],
    "cpe": "cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*"
}

Affected versions

7.*
7.10.0
7.10.1
7.10.10
7.10.2
7.10.3
7.10.4
7.10.5
7.10.6
7.10.7
7.10.8
7.10.9
7.11.0
7.11.1
7.11.2
7.11.3
7.11.4
7.11.5
7.11.6
7.11.7
7.12.0
7.12.1
7.12.2
7.12.3
7.12.4
7.12.5
7.12.6
7.12.7
7.13.0
7.13.1
7.13.2
7.13.3
7.13.4
7.13.5
7.13.6
8.*
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.1.0
8.1.1
8.1.2
8.1.3
8.2.0
8.2.1
8.2.2
8.3.0
8.3.1
8.3.2
8.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29197.json"