Authentication Bypass in Filament by Laravel
CVE-2026-84307

3.7LOW

Key Information:

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84307?

An authentication flaw exists in Filament that affects the multi-factor authentication (MFA) process for accounts that are denied access to the panel. When users with MFA enabled enter their password, those with valid credentials are presented with the MFA challenge, inadvertently confirming the existence of valid passwords. This issue arises from the flawed flow of authentication, allowing unauthenticated attackers to validate candidate passwords without bypassing the authentication since session creation does not occur. Effective remediation is available in versions 4.12.5 and 5.7.5.

Affected Version(s)

filament >= 4.0.0, < 4.12.5 < 4.0.0, 4.12.5

filament >= 5.0.0, < 5.7.5 < 5.0.0, 5.7.5

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.