stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP… (CVE-2026-100678)
Stoatchat versions before 0.15.5 do not enforce account-level attempt limits on multi-factor authentication (MFA) login challenges. This allows attackers who have obtained a user's password to repeatedly guess Time-based One-Time Password (TOTP) codes. The vulnerability arises because only IP-based rate limiting is applied, which can be bypassed by reusing MFA challenge tickets across multiple failed attempts and distributing guesses across different IP addresses.
AI Analysis
Technical Summary
Stoatchat before version 0.15.5 fails to enforce account-level attempt limits on MFA login challenges. Attackers who know a user's password can exploit this by guessing TOTP codes without effective account-level rate limiting. The system relies solely on IP-based rate limiting, which can be circumvented by reusing MFA challenge tickets and distributing attempts across multiple IP addresses, enabling attackers to bypass rate limits and potentially gain unauthorized account access.
Potential Impact
An attacker with knowledge of a user's password can bypass MFA protections by guessing TOTP codes due to the lack of account-level attempt limits. This can lead to unauthorized access to user accounts, compromising confidentiality. The integrity impact is limited as the attacker can only guess codes, and availability is not affected.
Mitigation Recommendations
A fix is available in Stoatchat version 0.15.5 that addresses this vulnerability by enforcing account-level attempt limits on MFA login challenges. Users and administrators should upgrade to version 0.15.5 or later to mitigate this issue.
stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP… (CVE-2026-100678)
Description
Stoatchat versions before 0.15.5 do not enforce account-level attempt limits on multi-factor authentication (MFA) login challenges. This allows attackers who have obtained a user's password to repeatedly guess Time-based One-Time Password (TOTP) codes. The vulnerability arises because only IP-based rate limiting is applied, which can be bypassed by reusing MFA challenge tickets across multiple failed attempts and distributing guesses across different IP addresses.
CVSS v3.1
Score 6.5medium
Affected software
pkg:github/stoatchat/stoatchatRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Stoatchat before version 0.15.5 fails to enforce account-level attempt limits on MFA login challenges. Attackers who know a user's password can exploit this by guessing TOTP codes without effective account-level rate limiting. The system relies solely on IP-based rate limiting, which can be circumvented by reusing MFA challenge tickets and distributing attempts across multiple IP addresses, enabling attackers to bypass rate limits and potentially gain unauthorized account access.
Potential Impact
An attacker with knowledge of a user's password can bypass MFA protections by guessing TOTP codes due to the lack of account-level attempt limits. This can lead to unauthorized access to user accounts, compromising confidentiality. The integrity impact is limited as the attacker can only guess codes, and availability is not affected.
Mitigation Recommendations
A fix is available in Stoatchat version 0.15.5 that addresses this vulnerability by enforcing account-level attempt limits on MFA login challenges. Users and administrators should upgrade to version 0.15.5 or later to mitigate this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qgwf-mjq4-r7pg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100678"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ab89bddf7a7c5410694203b
Added to database: 09/27/2026, 04:30:21 UTC
Last enriched: 09/27/2026, 04:42:15 UTC
Last updated: 09/28/2026, 01:47:40 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.