CVE-2026-104181
Received Received - Intake

Improper MFA Configuration in Filament Framework

Vulnerability report for CVE-2026-104181, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
filament filament From 4.0.0 (inc) to 4.13.3 (inc)
filament filament 5.8.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Filament, a Laravel development framework, between versions 4.0.0 and 4.13.3 and 5.8.3. It allows an attacker with access to an authenticated user session to manipulate app-based multi-factor authentication (MFA) settings without knowing the account password. This includes setting up MFA, obtaining recovery codes, or disabling MFA by supplying an existing app or recovery code.

Detection Guidance

To detect this vulnerability, check if your Filament versions are between 4.0.0 and 4.13.3 or 5.8.3. Review MFA settings for unauthenticated changes or missing password confirmations. Inspect logs for suspicious MFA configuration modifications or recovery code generation without password verification.

Impact Analysis

An attacker could gain unauthorized access to your account by changing MFA settings, locking you out, or obtaining recovery codes. This could lead to data breaches, unauthorized actions, or loss of account control if they have access to your session.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Organizations using affected Filament versions may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Upgrade Filament to version 4.13.3 or 5.8.3 or later to address the MFA management flaw. Review user accounts for unauthorized changes to app-based MFA settings and recovery codes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104181. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart