In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing authenticated users without the proper permissions to read apps-engine logs.
{
"cwe_ids": [
"CWE-284"
],
"cna_assigner": "hackerone",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29197.json"
}{
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "7.10.0"
},
{
"fixed": "7.10.10"
},
{
"introduced": "7.11.0"
},
{
"fixed": "7.11.7"
},
{
"introduced": "7.12.0"
},
{
"fixed": "7.12.7"
},
{
"introduced": "7.13.0"
},
{
"fixed": "7.13.6"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.4"
},
{
"introduced": "8.1.0"
},
{
"fixed": "8.1.3"
},
{
"introduced": "8.2.0"
},
{
"fixed": "8.2.2"
},
{
"introduced": "8.3.0"
},
{
"fixed": "8.3.2"
}
],
"cpe": "cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*"
}