RBAC bypass on App log endpoints via `permissionRequired` typo — any authenticated user reads admin-only Enterprise App logs

Disclosed: 2026-04-23 09:45:38 By arccode To rocket_chat
Medium
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOne
Report Stats
  • Report ID: 3589551
  • State: Closed
  • Substate: resolved
Share this report