What is CVE-2026-74869?
stoatchat versions before 0.15.0 contain a missing authorization vulnerability in the 'Subscribe' message handler. This allows authenticated attackers to enumerate members and monitor profile updates of private servers without having membership. Upgrading to version 0.15.0 is recommended to mitigate this issue.
Azərbaycanca: stoatchat-in 0.15.0-dən əvvəlki versiyalarında 'Subscribe' mesaj idarəedicisində çatışmayan avtorizasiya zəifliyi mövcuddur. Bu, autentifikasiya olunmuş hücumçulara üzv olmadıqları özəl serverlərdə üzvləri sadalamağa və profil yeniləmələrini izləməyə imkan verir. Təsirə məruz qalan sistemlərdə 0.15.0 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which versions of stoatchat are affected by CVE-2026-74869?
stoatchat versions before 0.15.0 are affected by this vulnerability. Upgrading to version 0.15.0 is recommended to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.