Multi-Factor Authentication Flaw in Filament by Filament PHP
CVE-2026-84306

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84306?

The Filament package for Laravel has a vulnerability in its multi-factor authentication (MFA) implementation. Versions from 4.0.0 to 4.12.6 and 5.7.6 allow an attacker, who gains access to a user's password and one app-based MFA code, to reuse that MFA code within the configured time window, even after a legitimate user has logged in using a newer code. This occurs because the code comparison mechanism does not correctly isolate the temporal window for accepted codes, allowing previously issued codes to remain valid. Email-based MFA remains unaffected by this issue. Ensure to update to the latest secure versions to mitigate this vulnerability.

Affected Version(s)

filament >= 4.0.0, < 4.12.6 < 4.0.0, 4.12.6

filament >= 5.0.0, < 5.7.6 < 5.0.0, 5.7.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.