CVE-2026-100679
Received Received - Intake

Authentication Bypass via MFA Ticket in StoaChat

Vulnerability report for CVE-2026-100679, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
stoatchat stoatchat to 0.15.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in stoatchat before version 0.15.5 allows attackers to bypass multi-factor authentication (MFA) by using their own valid MFA ticket with another user's session token. The system fails to validate that the MFA ticket belongs to the authenticated user, enabling unauthorized actions like disabling TOTP or viewing recovery codes without the victim's credentials.

Impact Analysis

If exploited, this vulnerability could allow attackers to bypass MFA protections, gain unauthorized access to your account, disable security features like TOTP, or retrieve recovery codes. This could lead to account takeover or unauthorized sensitive operations if an attacker obtains your session token.

Mitigation Strategies

Immediately upgrade stoatchat to version 0.15.5 or later to patch the vulnerability. Review logs for suspicious cross-account MFA ticket usage or unauthorized account modifications. Disable MFA ticket reuse if possible and monitor for unauthorized TOTP or recovery code changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100679. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart