MFA Bypass Vulnerability in Stoatchat by Stoatchat
CVE-2026-100679

7.1HIGH

Key Information:

Vendor

Stoatchat

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100679?

The MFA bypass vulnerability in Stoatchat prior to version 0.15.5 allows attackers to exploit misconfigured multi-factor authentication (MFA) mechanisms. By using a valid MFA ticket associated with their account in conjunction with another user's session token, attackers can execute actions such as disabling TOTP, accessing recovery codes, or carrying out other sensitive operations without requiring the victim's credentials. This flaw highlights the need for stringent verification mechanisms to link MFA tickets to the correct authenticated user.

Affected Version(s)

stoatchat 0 < 0.15.5

stoatchat 0.15.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.