PT-2026-84401 · Filament · Filament
CVE-2026-84307
·
Published
2026-09-01
·
Updated
2026-09-02
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Filament versions prior to 4.12.5
Filament versions prior to 5.7.5
Description
The login page presents the multi-factor authentication (MFA) challenge before evaluating the
canAccessPanel() function. For accounts where canAccessPanel() denies access, submitting a correct password triggers the MFA challenge, whereas an incorrect password returns a generic authentication failure. This behavior allows an unauthenticated attacker to verify if a password is valid for a specific account. Additionally, if email-based MFA is configured, a login code is sent to the account holder when the correct password is provided. This issue only affects accounts that have MFA enabled and are denied panel access. Authentication is not bypassed because the access check occurs after the challenge and no session is created.Recommendations
Update to version 4.12.5.
Update to version 5.7.5.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filament