Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stoatchat
Stoatchat stoatchat |
|
| Vendors & Products |
Stoatchat
Stoatchat stoatchat |
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's credentials. | |
| Title | stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T13:23:41.637Z
Reserved: 2026-09-26T02:36:51.809Z
Link: CVE-2026-100679
No data.
Status : Received
Published: 2026-09-26T14:16:51.993
Modified: 2026-09-26T14:16:51.993
Link: CVE-2026-100679
No data.
OpenCVE Enrichment
Updated: 2026-09-26T17:00:14Z
-
CWE-639
Authorization Bypass Through User-Controlled Key