Sceawere

Vulnerability Detail

CVE-2026-77567UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Filament MFA Bypass Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
2h ago
Vendor
filamentphp
Product
filament
Attack Type
CWE-287: Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-24T21:17:48.150Z",
  "pubdate": "2026-08-24T21:17:48.150Z",
  "executiveSummary": "An authentication bypass vulnerability exists in Filament, a collection of full-stack components for accelerated Laravel development, specifically within the app-based multi-factor authentication (MFA) challenge-form handling mechanism. The flaw permits attackers to bypass app-based multi-factor authentication requirements under conditions where recovery codes are enabled.\nThe vulnerability directly impacts applications utilizing Filament versions prior to 4.12.0 and 5.7.0 that implement app-based multi-factor authentication. Email-based multi-factor authentication configurations remain unaffected by this issue.\nThe risk implications are severe, as successful exploitation enables unauthorized access to restricted accounts and administrative interfaces without satisfying the requisite multi-factor authentication checks. Exploitation requires an attacker to interact with the authentication challenge workflow where app-based MFA and recovery codes are simultaneously active.\nNo specific attacker capabilities or advanced privileges are required beyond standard network access to the target application's authentication endpoints, provided recovery codes are enabled and app-based MFA is targeted.",
  "technicalDetails": "The root cause of the vulnerability stems from incorrect handling of required fields within the challenge-form component of Filament's app-based multi-factor authentication implementation. When recovery codes are enabled alongside app-based MFA, the validation logic improperly enforces the completion or verification of the primary multi-factor authentication challenge.\nThe vulnerable component resides within Filament's authentication challenge-form handling logic for app-based multi-factor authentication. Affected versions encompass all releases prior to 4.12.0 and 5.7.0.\nThe exploitation method relies on manipulating or omitting input fields during the multi-factor authentication challenge phase. Because the required-field validation is incorrectly configured when recovery codes are enabled, the validation routine fails to block requests that bypass the primary app-based token verification.\nThe attack flow proceeds as follows: First, an attacker authenticates with valid primary credentials (username and password) for a target account that has app-based multi-factor authentication and recovery codes enabled. Upon being presented with the multi-factor authentication challenge form, the attacker submits crafted HTTP requests or interacts with the form in a manner that exploits the flawed required-field handling. Due to the improper validation logic, the application incorrectly interprets the submission as valid or bypasses the necessary verification checks, granting the attacker authenticated session access.\nAuthentication requirements for the attack involve valid primary credentials. No elevated privileges are required prior to exploitation, and the network exposure is tied to the web application's public authentication endpoints. Post-exploitation impact results in full unauthorized session establishment and access to the compromised user's privileges and data."
}
CVE-2026-77567: Filament MFA Bypass Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere