Stoatchat · Stoatchat · CVE-2026-74869
**Name of the Vulnerable Software and Affected Versions**
stoatchat versions prior to 0.15.0
**Description**
A missing authorization issue exists in the Subscribe message handler. Authenticated attackers can enumerate members and monitor profile updates of private servers they are not members of. By sending a Subscribe message containing an arbitrary server ID, an attacker can subscribe to a server's member-update topic and receive live UserUpdate events, which include display names, avatars, and status changes.
**Recommendations**
Update stoatchat to version 0.15.0 or later.