CVE-2026-104181: Authentication Bypass and Privilege Escalation in Filament Multi-Factor Authentication
Vulnerability ID: CVE-2026-104181
CVSS Score: 5.4
Published: 2026-10-05
An authentication bypass and privilege escalation vulnerability exists in Filament (filamentphp/filament) due to missing password verification during multi-factor authentication (MFA) setup and management. An attacker with access to an active session can modify or disable MFA, leading to account hijacking.
TL;DR
Filament failed to prompt for the user's password when modifying, disabling, or establishing app-based multi-factor authentication (MFA). If an attacker hijacked an active session, they could bind their own MFA token or disable the user's protection without knowing the master password.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-306
- Attack Vector: Network (AV:N)
- CVSS Score: 5.4
- EPSS Score: 0.0034
- Impact: Account Takeover / Multi-Factor Authentication Bypass
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- Filament Panel Builder application instances using app-based multi-factor authentication (TOTP).
-
Filament: >= 4.0.0, < 4.13.3 (Fixed in:
4.13.3) -
Filament: >= 5.0.0, < 5.8.3 (Fixed in:
5.8.3)
Code Analysis
Commit: 6d4dae6
Require password confirmation for modifying app-based MFA configurations.
Exploit Details
- GitHub: GitHub Security Advisory details explaining the authentication vulnerability.
Mitigation Strategies
- Upgrade Filament dependencies to version 4.13.3 or higher (for v4 installations) or 5.8.3 or higher (for v5 installations).
- Enforce session timeout policies to minimize the window of opportunity for session hijacking.
- Implement robust Content Security Policies (CSP) to mitigate Cross-Site Scripting (XSS) risks that could lead to session access.
Remediation Steps:
- Open the project's composer.json file.
- Update the 'filament/filament' dependency line to reference '^4.13.3' or '^5.8.3' depending on the major version in use.
- Run the command: composer update filament/filament
- Verify the installed version in composer.lock to ensure the patched release is active.
- Clear application and route caches using: php artisan config:clear && php artisan cache:clear
References
Read the full report for CVE-2026-104181 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)