rootpwn

critical · CVSS v3 8.8 · CVSS v4 7.1

CVE-2026-100679

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypas…

Description

stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's credentials.

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
7.1
EPSS
—

← All CVEs