CVE-2026-23477 is a medium severity vulnerability with a CVSS score of 6.5. Active exploits exist with no official patch available - immediate mitigation is required.
Very low probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth application, as long as the user knows its ID, including potentially sensitive fields such as client_id and client_secret. This vulnerability is fixed in 6.12.0.
| Vendor | Product |
|---|---|
| Rocket.chat | Rocket.chat |
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.