PT-2026-76605 · Stoatchat · Stoatchat

·

CVE-2026-74869

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions stoatchat versions prior to 0.15.0
Description A missing authorization issue exists in the Subscribe message handler. Authenticated attackers can enumerate members and monitor profile updates of private servers they are not members of. By sending a Subscribe message containing an arbitrary server ID, an attacker can subscribe to a server's member-update topic and receive live UserUpdate events, which include display names, avatars, and status changes.
Recommendations Update stoatchat to version 0.15.0 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74869
GHSA-JJ3J-9QR7-JGFC

Affected Products

Stoatchat