5.4

CVE-2026-104181

Filament: Multi-factor authentication (app) management actions do not require password reauthentication

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerfilamentphp
≫
Produkt filament
Version >= 4.0.0, < 4.13.2
Status affected
Version >= 5.0.0, < 5.8.2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.251
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://github.com/filamentphp/filament/security/advisories/GHSA-7m6h-rg42-m449
https://github.com/filamentphp/filament/pull/20522
https://github.com/filamentphp/filament/commit/6d4dae6d7a94ce5aefd7ed4dc836acb0e6b71bb1
https://github.com/filamentphp/filament/releases/tag/v4.13.3
https://github.com/filamentphp/filament/releases/tag/v5.8.3