CVE-2026-100678: stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting

Published Sep 26, 2026
·
Updated

stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access.

Affected Software

1 affected component
stoatchat<0.15.5

Event History

Sep 26, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker must know the target account's password and must then guess its TOTP MFA code. No additional privileges or user interaction are required.

2

Can IP-based rate limiting prevent exploitation?

Not reliably. The affected MFA flow applies rate limiting only by IP address, so an attacker can distribute guesses across multiple IP addresses and reuse the same MFA challenge ticket after failed attempts.

3

Which deployments should be prioritized for remediation?

Prioritize stoatchat deployments before version 0.15.5 that use TOTP MFA, particularly where attackers could obtain or guess user passwords. Accounts with high-value access are at increased risk because successful code guessing can result in account access.

4

How can exposure be reduced before upgrading?

The provided information identifies IP-based rate limiting as bypassable and does not specify an effective workaround. Upgrade stoatchat to version 0.15.5 or later to address the missing account-level attempt limits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203