CVE-2026-48166Medium· 5.3▾ SunlitFilament: Timing-based user enumeration on login page
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.3%
The login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresses. The impact is limited to disclosing whether an account exists for a given email.
filament/filament >= 4.0.0, <= 4.11.4filament/filament >= 5.0.0, <= 5.6.4Upgrade to a patched release:
filament/filament 4.11.5filament/filament 5.6.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77567High· 8.1Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84307Low· 3.7Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84306Medium· 6.5Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-48500Medium· 6.5Filament: Unauthenticated temporary file upload on auth pages
CVE-2026-48505High· 7.4Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
CVE-2026-48067Medium· 6.5Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields