Multi-Factor Authentication Bypass Vulnerability in Filament by Spatie
CVE-2026-77567
8.1HIGH
What is CVE-2026-77567?
Filament, a suite of full-stack components designed to accelerate Laravel development, has a vulnerability related to its multi-factor authentication feature. Specifically, prior to versions 4.12.0 and 5.7.0, inadequate handling of challenge-form required-field configurations could allow attackers to bypass app-based multi-factor authentication when recovery codes are activated. It's important to note that email-based multi-factor authentication remains unaffected by this issue. Users are strongly advised to upgrade to the latest versions to secure their applications.
Affected Version(s)
filament >= 4.0.0, < 4.12.0 < 4.0.0, 4.12.0
filament >= 5.0.0, < 5.7.0 < 5.0.0, 5.7.0
