CVE-2026-100679: stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket
stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
stoatchatto a version that resolves this vulnerability.Fixed in 0.15.5
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs a valid MFA ticket for an account they control and a victim's session token. The attack is network-accessible, requires low complexity, requires low privileges, and does not require user interaction.
Which deployments should be considered affected?
stoatchat versions before 0.15.5 are affected. Upgrading to 0.15.5 or later addresses the vulnerable version range identified here.
What could an attacker do with a victim's session token?
An attacker can use their own valid MFA ticket with the victim's session token to bypass MFA for sensitive operations. Documented impacts include disabling TOTP, viewing recovery codes, and performing other sensitive actions without the victim's credentials.