PT-2026-99350 · Stoatchat · Stoatchat
CVE-2026-100679
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
stoatchat versions prior to 0.15.5
Description
An issue exists where the system fails to validate that Multi-Factor Authentication (MFA) tickets belong to the authenticated user. This allows an attacker to bypass MFA by using a valid ticket from their own account in conjunction with another user's session token. Consequently, an attacker can disable Time-based One-Time Password (TOTP) settings, view recovery codes, or perform other sensitive operations without the victim's credentials.
Recommendations
Update stoatchat to version 0.15.5 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stoatchat