Back

MEDIUM

Filament: Multi-factor authentication (app) management actions do not require password reauthentication

Published Oct 1, 2026

Description

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Oct 1, 2026
NVD
Status Received
Modified Oct 1, 2026
Red Hat
Severity n/a
Public date n/a