DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-104181: CVE-2026-104181: Authentication Bypass and Privilege Escalation in Filament Multi-Factor Authentication

CVE-2026-104181: Authentication Bypass and Privilege Escalation in Filament Multi-Factor Authentication

Vulnerability ID: CVE-2026-104181
CVSS Score: 5.4
Published: 2026-10-05

An authentication bypass and privilege escalation vulnerability exists in Filament (filamentphp/filament) due to missing password verification during multi-factor authentication (MFA) setup and management. An attacker with access to an active session can modify or disable MFA, leading to account hijacking.

TL;DR

Filament failed to prompt for the user's password when modifying, disabling, or establishing app-based multi-factor authentication (MFA). If an attacker hijacked an active session, they could bind their own MFA token or disable the user's protection without knowing the master password.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-306
  • Attack Vector: Network (AV:N)
  • CVSS Score: 5.4
  • EPSS Score: 0.0034
  • Impact: Account Takeover / Multi-Factor Authentication Bypass
  • Exploit Status: poc
  • KEV Status: Not Listed

Affected Systems

  • Filament Panel Builder application instances using app-based multi-factor authentication (TOTP).
  • Filament: >= 4.0.0, < 4.13.3 (Fixed in: 4.13.3)
  • Filament: >= 5.0.0, < 5.8.3 (Fixed in: 5.8.3)

Code Analysis

Commit: 6d4dae6

Require password confirmation for modifying app-based MFA configurations.

Exploit Details

  • GitHub: GitHub Security Advisory details explaining the authentication vulnerability.

Mitigation Strategies

  • Upgrade Filament dependencies to version 4.13.3 or higher (for v4 installations) or 5.8.3 or higher (for v5 installations).
  • Enforce session timeout policies to minimize the window of opportunity for session hijacking.
  • Implement robust Content Security Policies (CSP) to mitigate Cross-Site Scripting (XSS) risks that could lead to session access.

Remediation Steps:

  1. Open the project's composer.json file.
  2. Update the 'filament/filament' dependency line to reference '^4.13.3' or '^5.8.3' depending on the major version in use.
  3. Run the command: composer update filament/filament
  4. Verify the installed version in composer.lock to ensure the patched release is active.
  5. Clear application and route caches using: php artisan config:clear && php artisan cache:clear

References


Read the full report for CVE-2026-104181 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)