MFA Bypass Vulnerability in Stoatchat by Stoatchat
CVE-2026-100679
7.1HIGH
What is CVE-2026-100679?
The MFA bypass vulnerability in Stoatchat prior to version 0.15.5 allows attackers to exploit misconfigured multi-factor authentication (MFA) mechanisms. By using a valid MFA ticket associated with their account in conjunction with another user's session token, attackers can execute actions such as disabling TOTP, accessing recovery codes, or carrying out other sensitive operations without requiring the victim's credentials. This flaw highlights the need for stringent verification mechanisms to link MFA tickets to the correct authenticated user.
Affected Version(s)
stoatchat 0 < 0.15.5
stoatchat 0.15.5
