๐Ÿ” CVE Alert

CVE-2026-104181

MEDIUM 5.4

Filament: Multi-factor authentication (app) management actions do not require password reauthentication

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.

CWE CWE-306
Vendor filamentphp
Product filament
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for filamentphp filament

Be the first to know when new medium vulnerabilities affecting filamentphp filament are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

filamentphp / filament
>= 4.0.0, < 4.13.2 >= 5.0.0, < 5.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/filamentphp/filament/security/advisories/GHSA-7m6h-rg42-m449 github.com: https://github.com/filamentphp/filament/pull/20522 github.com: https://github.com/filamentphp/filament/commit/6d4dae6d7a94ce5aefd7ed4dc836acb0e6b71bb1 github.com: https://github.com/filamentphp/filament/releases/tag/v4.13.3 github.com: https://github.com/filamentphp/filament/releases/tag/v5.8.3