Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth application, as long as the user knows its ID, including potentially sensitive fields such as client_id and client_secret. This vulnerability is fixed in 6.12.0.
History

Wed, 14 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth application, as long as the user knows its ID, including potentially sensitive fields such as client_id and client_secret. This vulnerability is fixed in 6.12.0.
Title Rocket.Chat Unauthorized Access to OAuth App Details
Weaknesses CWE-269
CWE-862
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-14T21:14:08.081Z

Reserved: 2026-01-13T15:47:41.627Z

Link: CVE-2026-23477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-14T19:16:47.990

Modified: 2026-01-14T19:16:47.990

Link: CVE-2026-23477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.