CVE-2026-23477 | RocketChat Rocket.Chat up to 6.11.x API Endpoint /api/v1/oauth-apps.get client_id/client_secret privileges management (GHSA-g4wm-fg3c-g4p2 / EUVD-2026-2667)
A vulnerability was found in RocketChat Rocket.Chat up to 6.11.x. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/v1/oauth-apps.get of the component API Endpoint. This manipulation of the argument client_id/client_secret causes improper privilege management.
This vulnerability appears as CVE-2026-23477. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.