Sceawere

Vulnerability Detail

CVE-2026-104181UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Filament Improper MFA Authentication Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
1d ago
Vendor
filamentphp
Product
filament
Attack Type
CWE-306: Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-01T21:17:18.810Z",
  "pubdate": "2026-10-01T21:17:18.810Z",
  "executiveSummary": "A security vulnerability exists in Filament versions 4.0.0 through 4.13.2 and 5.0.0 through 5.8.2 regarding app-based multi-factor authentication (MFA) management.\nThe vulnerability is characterized by a failure to perform adequate re-authentication checks, specifically the absence of mandatory password verification when modifying MFA settings.\nAn attacker possessing an active session for an authenticated user can modify, enable, or disable app-based MFA configurations and regenerate recovery codes without knowledge of the account password.\nWhile this flaw does not permit unauthenticated initial access, it allows an attacker to hijack MFA controls, potentially leading to unauthorized account access or the lockout of legitimate users.\nEmail-based MFA remains unaffected by this flaw. The risk is significant for multi-user environments where session hijacking or physical access to an authenticated device may occur.\nThe vulnerability is resolved by enforcing password verification for sensitive MFA management actions in the specified patched versions.",
  "technicalDetails": "The root cause of the vulnerability lies in the insufficient authorization logic within the Filament app-based MFA management workflow. The application fails to implement a secondary verification step (password confirmation) when a user attempts to change security-critical MFA settings.\nIn the affected versions (4.0.0 to 4.13.2 and 5.0.0 to 5.8.2), the system assumes that possessing an active authenticated session is sufficient authorization to alter MFA state. This creates a critical weakness if the session is intercepted, leaked, or if a device is left logged in.\nThe attack flow follows a predictable pattern: 1. An attacker gains access to an authenticated user's active session. 2. The attacker navigates to the MFA management settings. 3. The attacker adds a new app-based MFA device or disables existing MFA protections. 4. The system updates the account security configuration without triggering a password challenge. 5. If the attacker disables MFA or swaps the secret, they can subsequently generate new recovery codes, effectively seizing administrative or user-level control over the security posture of the account.\nBecause the application logic does not validate the current account password during these transactions, the integrity of the MFA setup is compromised. The vulnerability specifically targets the app-based MFA component. Email-based MFA is exempt because it likely utilizes different verification paths not impacted by the flawed logic.\nThe impact is twofold: denial of service through user lockout (by replacing the MFA secret and locking the legitimate user out) and persistent unauthorized access (by ensuring the attacker possesses valid MFA tokens). This is classified as a privilege escalation/authentication bypass within the context of security settings management.\nThis vulnerability requires an established, active session, making it a post-authentication escalation issue rather than a remote unauthenticated exploit. There is no network exposure in the traditional sense; the vulnerability exists within the application's internal API controllers handling the MFA state changes."
}
CVE-2026-104181: Filament Improper MFA Authentication Bypass (MEDIUM Severity, CVSS: 5.4) | Sceawere