CVE-2026-32994
Summary
| CVE | CVE-2026-32994 |
|---|---|
| State | PUBLISHED |
| Assigner | hackerone |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-19 05:16:23 UTC |
| Updated | 2026-05-19 14:50:07 UTC |
| Description | The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply providing the target message ID. The endpoint fetches the message via Messages.findOneById(messageId) with no room access check (canAccessRoomIdAsync is never called), returning the complete IMessage object including message text, sender info, room ID, timestamps, and markdown content. |
Risk And Classification
Primary CVSS: v3.0 5.3 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.000280000 probability, percentile 0.084520000 (date 2026-05-26)
Problem Types: CWE-284 | CWE-284 CWE-284 Improper Access Control - Generic
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 3.0 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Rocket.Chat | Rocket.Chat | affected 8.5.0 semver | Not specified |
| CNA | Rocket.Chat | Rocket.Chat | affected 8.4.2 semver | Not specified |
| CNA | Rocket.Chat | Rocket.Chat | affected 8.3.4 semver | Not specified |
| CNA | Rocket.Chat | Rocket.Chat | affected 8.2.4 semver | Not specified |
| CNA | Rocket.Chat | Rocket.Chat | affected 8.1.5 semver | Not specified |
| CNA | Rocket.Chat | Rocket.Chat | affected 8.0.6 semver | Not specified |
| CNA | Rocket.Chat | Rocket.Chat | affected 7.13.8 semver | Not specified |
| CNA | Rocket.Chat | Rocket.Chat | affected 7.10.12 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| hackerone.com/reports/3713682 | [email protected] | hackerone.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.