Threat intelligence dashboard
CVE-2026-100679high

stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's credentials.

Risk score

7.1

CVSS 4.0

Vendor
stoatchat
Product
stoatchat
CWE
CWE-639
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

stoatchat

stoatchat

Version / rangeStatusType
0 to before 0.15.5affectedsemver
0.15.5unaffectedsemver

Technical metrics

7.1

CVSS 4.0

Severity
high
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

8.8

CVSS 3.1

Severity
high
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H