{"id":"CVE-2026-104181","title":"Filament is a collection of full-stack components for accelerated Laravel development","summary":"Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current pa…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-306"],"vendor":"filamentphp","product":"filament","affected":["filament >= 4.0.0, < 4.13.2","filament >= 5.0.0, < 5.8.2"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T21:17:18.810","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104181","references":[{"url":"https://github.com/filamentphp/filament/commit/6d4dae6d7a94ce5aefd7ed4dc836acb0e6b71bb1","label":"security-advisories@github.com"},{"url":"https://github.com/filamentphp/filament/pull/20522","label":"security-advisories@github.com"},{"url":"https://github.com/filamentphp/filament/releases/tag/v4.13.3","label":"security-advisories@github.com"},{"url":"https://github.com/filamentphp/filament/releases/tag/v5.8.3","label":"security-advisories@github.com"},{"url":"https://github.com/filamentphp/filament/security/advisories/GHSA-7m6h-rg42-m449","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T21:00:32.275Z","slug":"CVE-2026-104181","body":"## Overview\n\nFilament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}