← Vulnerability feed

Vulnerability record · CVE-2021-22911 · published 27 May 2021

CVE-2021-22911: Rocket.Chat improper input sanitization allows unauthenticated NoSQL injection

RRocket.Chat · Rocket.Chat

Rocket.Chat server versions 3.11, 3.12 and 3.13 fail to properly sanitize input, allowing unauthenticated NoSQL injection. The flaw can escalate to remote code execution, making it a serious risk for exposed chat servers.

9.8 CVSS 3.1 Critical EPSS 95% · top 0.1% CWE-75 · CWE-75
9.8CVSS 3.1 base score, v2 7.5
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with unauthenticated network exploitation and public exploit code, plus very high EPSS, makes this an urgent patching priority.

What it is

Rocket.Chat server versions 3.11, 3.12 and 3.13 fail to properly sanitize input, allowing unauthenticated NoSQL injection. The flaw can escalate to remote code execution, making it a serious risk for exposed chat servers.

Impact

An unauthenticated attacker can inject NoSQL operators to manipulate queries and potentially achieve remote code execution on the server. This can lead to full compromise of the Rocket.Chat instance and its data.

Attack surface

The vulnerability is network-reachable with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. It is exploited through crafted input to the Rocket.Chat server.

Exploitation

Public exploit code is referenced in Packetstorm, SonarSource and HackerOne advisories, and EPSS is 0.95242 (99.862 percentile), indicating very high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade Rocket.Chat to a patched version newer than 3.13 as soon as possible.
  • If immediate upgrade is not possible, restrict network access to the Rocket.Chat server to trusted users only.
  • Monitor vendor advisories and apply any hotfixes or configuration hardening guidance for NoSQL injection.
  • Review and sanitize all user-supplied input handling in custom integrations or plugins.
  • Enable authentication and rate limiting where feasible to reduce exposure.

Detection

  • Inspect Rocket.Chat server logs for unusual NoSQL query patterns or errors containing operators like $where, $ne, or $gt.
  • Monitor for unexpected outbound connections or process execution from the Rocket.Chat server host.
  • Use network detection to identify exploit attempts against Rocket.Chat endpoints based on known public exploit signatures.
  • Audit authentication and API access logs for anomalous unauthenticated requests to Rocket.Chat.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22911 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-58066Rocket.chat improper authentication vulnerabilityRocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind t…EPSS 0.38%9.8CVE-2026-29198Rocket.chat sql injection vulnerabilityIn Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover o…EPSS 0.56%9.8CVE-2023-28316Rocket.chat vulnerabilityA security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidate…EPSS 0.72%9.8CVE-2022-44567Rocket.chat os command injection vulnerabilityA command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChat…EPSS 1.7%9.8CVE-2021-22910Rocket.chat vulnerabilityA sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result i…EPSS 2.3%9.8CVE-2020-29594Rocket.chat vulnerabilityRocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.EPSS 1.6%9.8CVE-2017-1000493Rocket.chat injection vulnerabilityRocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeoverEPSS 1.7%9.3CVE-2026-48616Rocket.chat improper access control vulnerabilityRocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2021-22911), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.