{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afilamentphpfilament/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:filamentphp:filament:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-77567"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["filament (\u003e= 4.0.0, \u003c 4.12.0)","filament (\u003e= 5.0.0, \u003c 5.7.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["FilamentPHP"],"content_html":"\u003cp\u003eFilament, a popular framework for building administrative panels, contains a critical authentication flaw identified as CVE-2026-77567. The vulnerability exists in the challenge handling logic for app-based multi-factor authentication (MFA). When recovery codes are enabled for a user, the application fails to properly validate the second-factor token, allowing an attacker to bypass the MFA challenge entirely. This flaw is specific to app-based MFA and does not affect configurations using email-based authentication. The issue impacts Filament version branches 4.x (prior to 4.12.0) and 5.x (prior to 5.7.0). Successful exploitation grants an attacker unauthorized access to protected accounts, bypassing a significant layer of security intended to prevent account takeover.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe risk to organizations using Filament for administrative interfaces, as it allows unauthorized users with valid primary credentials to bypass the second-factor requirement. This essentially negates the security benefits of MFA for affected users, significantly increasing the likelihood of account compromise, data exfiltration, and unauthorized administrative actions within the application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching affected systems to mitigate the risk of account takeover.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the filament/filament package to version 4.12.0 or 5.7.0 immediately.\u003c/li\u003e\n\u003cli\u003eDisable app-based MFA or recovery codes as a temporary workaround until patching is complete if the application must remain internet-facing.\u003c/li\u003e\n\u003cli\u003eAudit authentication logs for unusual login patterns or failed attempts followed by successful access to user accounts in the administrative panel.\u003c/li\u003e\n\u003cli\u003eReview administrative user accounts for unauthorized changes or configuration modifications made since the deployment of vulnerable versions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T00:00:24Z","date_published":"2026-09-02T00:00:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-filament-mfa-bypass/","summary":"An improper authentication vulnerability in the Filament framework allows attackers to bypass app-based multi-factor authentication when recovery codes are enabled.","title":"Authentication Bypass in Filament Framework MFA","url":"https://feed.craftedsignal.io/briefs/2026-09-filament-mfa-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:filamentphp:filament:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}