CVE-2026-100679
8.8 HIGHpublic exploit availablePublished 2026-09-26 · Updated 2026-09-28
AI risk analysis
- Summary
- stoatchat before 0.15.5 allows attackers to bypass multi-factor authentication (MFA) by using their own valid MFA ticket with another user's session token, enabling unauthorized access to sensitive operations.
- Exploitability
- Exploitation requires attackers to have a valid MFA ticket and a victim's session token, making it moderately difficult.
- Blast radius
- If exploited, attackers can perform sensitive operations such as disabling TOTP or viewing recovery codes, potentially leading to significant data breaches.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to stoatchat 0.15.5 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's credentials.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-639
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-71420PoC
- HIGHCVE-2026-100670PoC
- CRITICALCVE-2026-101084PoC
- HIGHCVE-2026-48826PoC
- HIGHCVE-2026-48976PoC
- MEDIUMCVE-2026-52743PoC
- MEDIUMCVE-2026-55625PoC
- HIGHCVE-2026-55739PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.