Multi-Factor Authentication Flaw in Filament by Filament PHP
CVE-2026-84306
6.5MEDIUM
What is CVE-2026-84306?
The Filament package for Laravel has a vulnerability in its multi-factor authentication (MFA) implementation. Versions from 4.0.0 to 4.12.6 and 5.7.6 allow an attacker, who gains access to a user's password and one app-based MFA code, to reuse that MFA code within the configured time window, even after a legitimate user has logged in using a newer code. This occurs because the code comparison mechanism does not correctly isolate the temporal window for accepted codes, allowing previously issued codes to remain valid. Email-based MFA remains unaffected by this issue. Ensure to update to the latest secure versions to mitigate this vulnerability.
Affected Version(s)
filament >= 4.0.0, < 4.12.6 < 4.0.0, 4.12.6
filament >= 5.0.0, < 5.7.6 < 5.0.0, 5.7.6
