PT-2026-84401 · Filament · Filament

CVE-2026-84307

·

Published

2026-09-01

·

Updated

2026-09-02

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Filament versions prior to 4.12.5 Filament versions prior to 5.7.5
Description The login page presents the multi-factor authentication (MFA) challenge before evaluating the canAccessPanel() function. For accounts where canAccessPanel() denies access, submitting a correct password triggers the MFA challenge, whereas an incorrect password returns a generic authentication failure. This behavior allows an unauthenticated attacker to verify if a password is valid for a specific account. Additionally, if email-based MFA is configured, a login code is sent to the account holder when the correct password is provided. This issue only affects accounts that have MFA enabled and are denied panel access. Authentication is not bypassed because the access check occurs after the challenge and no session is created.
Recommendations Update to version 4.12.5. Update to version 5.7.5.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84307
GHSA-XWPV-PQXP-5V36

Affected Products

Filament