Multi-Factor Authentication Bypass Vulnerability in Filament by Spatie
CVE-2026-77567

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-77567?

Filament, a suite of full-stack components designed to accelerate Laravel development, has a vulnerability related to its multi-factor authentication feature. Specifically, prior to versions 4.12.0 and 5.7.0, inadequate handling of challenge-form required-field configurations could allow attackers to bypass app-based multi-factor authentication when recovery codes are activated. It's important to note that email-based multi-factor authentication remains unaffected by this issue. Users are strongly advised to upgrade to the latest versions to secure their applications.

Affected Version(s)

filament >= 4.0.0, < 4.12.0 < 4.0.0, 4.12.0

filament >= 5.0.0, < 5.7.0 < 5.0.0, 5.7.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.