← Back to search

CVE-2026-100679

8.8 HIGHpublic exploit available

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
stoatchat before 0.15.5 allows attackers to bypass multi-factor authentication (MFA) by using their own valid MFA ticket with another user's session token, enabling unauthorized access to sensitive operations.
Exploitability
Exploitation requires attackers to have a valid MFA ticket and a victim's session token, making it moderately difficult.
Blast radius
If exploited, attackers can perform sensitive operations such as disabling TOTP or viewing recovery codes, potentially leading to significant data breaches.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to stoatchat 0.15.5 or later.
auth-bypassmfaweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's credentials.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-639

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.