{"id":"CVE-2026-100679","published":"2026-09-26T14:16:51.993","lastModified":"2026-09-28T18:17:15.007","description":"stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's credentials.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://github.com/stoatchat/stoatchat/security/advisories/GHSA-gwg6-q3c3-97cx","tags":[]},{"url":"https://www.vulncheck.com/advisories/stoatchat-before-0.15.5-mfa-bypass-via-cross-account-ticket","tags":[]},{"url":"https://github.com/stoatchat/stoatchat/security/advisories/GHSA-gwg6-q3c3-97cx","tags":[]}],"exploitRefs":[{"url":"https://github.com/stoatchat/stoatchat/security/advisories/GHSA-gwg6-q3c3-97cx","tags":[]},{"url":"https://github.com/stoatchat/stoatchat/security/advisories/GHSA-gwg6-q3c3-97cx","tags":[]}],"hasPoc":true,"ai":{"summary":"stoatchat before 0.15.5 allows attackers to bypass multi-factor authentication (MFA) by using their own valid MFA ticket with another user's session token, enabling unauthorized access to sensitive operations.","exploitability":"Exploitation requires attackers to have a valid MFA ticket and a victim's session token, making it moderately difficult.","blast_radius":"If exploited, attackers can perform sensitive operations such as disabling TOTP or viewing recovery codes, potentially leading to significant data breaches.","remediation":"Upgrade to stoatchat 0.15.5 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","mfa","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:03:32.874Z"}}