CVE-2026-77567High· 8.1▾ TwilightFilament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
filament/filament >= 4.0.0, < 4.12.0filament/filament >= 5.0.0, < 5.7.0Patched in:
filament/filament 4.12.0filament/filament 5.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84307Low· 3.7Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84306Medium· 6.5Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-48166Medium· 5.3Filament: Timing-based user enumeration on login page
CVE-2026-48500Medium· 6.5Filament: Unauthenticated temporary file upload on auth pages
CVE-2026-48505High· 7.4Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
CVE-2023-49105Critical· 9.8An issue was discovered in ownCloud owncloud/core before 10.13.1