5.4
CVE-2026-104181
- EPSS 0.34%
- Veröffentlicht 01.10.2026 20:02:30
- Zuletzt bearbeitet 06.10.2026 03:16:59
- Erkennungen
Filament: Multi-factor authentication (app) management actions do not require password reauthentication
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerfilamentphp
≫
Produkt
filament
Version
>= 4.0.0, < 4.13.2
Status
affected
Version
>= 5.0.0, < 5.8.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.251 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://github.com/filamentphp/filament/security/advisories/GHSA-7m6h-rg42-m449
https://github.com/filamentphp/filament/pull/20522
https://github.com/filamentphp/filament/commit/6d4dae6d7a94ce5aefd7ed4dc836acb0e6b71bb1
https://github.com/filamentphp/filament/releases/tag/v4.13.3
https://github.com/filamentphp/filament/releases/tag/v5.8.3