PT-2026-99350 · Stoatchat · Stoatchat

CVE-2026-100679

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions stoatchat versions prior to 0.15.5
Description An issue exists where the system fails to validate that Multi-Factor Authentication (MFA) tickets belong to the authenticated user. This allows an attacker to bypass MFA by using a valid ticket from their own account in conjunction with another user's session token. Consequently, an attacker can disable Time-based One-Time Password (TOTP) settings, view recovery codes, or perform other sensitive operations without the victim's credentials.
Recommendations Update stoatchat to version 0.15.5 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100679
GHSA-GWG6-Q3C3-97CX

Affected Products

Stoatchat