PT-2026-84400 · Filament · Filament
CVE-2026-84306
·
Published
2026-08-05
·
Updated
2026-09-02
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Filament versions prior to 4.12.6
Filament versions prior to 5.7.6
Description
An issue exists in the handling of one-time codes for app-based multi-factor authentication (MFA). The
AppAuthentication::verifyCode() function uses a cache key derived from both the app authentication secret and the submitted TOTP code, which isolates the newest accepted timestep by code rather than by secret. This allows a previously issued app-based MFA code to be accepted even after a newer code has been used, provided the code is still within the accepted time window (approximately four minutes by default). An attacker who obtains a user's password and one app-based MFA code can use that code for the remainder of the window, even if the legitimate user has already logged in with a newer code. Email-based MFA is not affected.Recommendations
Update to version 4.12.6.
Update to version 5.7.6.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filament