CVE-2026-77567: Filament: App-based MFA can be bypassed when recovery codes are enabled
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Filamentto a version that resolves this vulnerability.Fixed in 4.12.0 - Upgrade
Upgrade
Filamentto a version that resolves this vulnerability.Fixed in 5.7.0
Event History
Frequently Asked Questions
Which deployments are affected?
Filament deployments using app-based MFA with recovery codes enabled are affected if they run a version earlier than 4.12.0 or 5.7.0. Email-based MFA is not affected.
What access does an attacker need to exploit this issue?
The severity vector indicates that an attacker needs low-level privileges and can exploit the issue over the network without user interaction. The vulnerability permits bypass of app-based MFA because of incorrect required-field handling in the challenge form.
What should be prioritized for remediation?
Upgrade Filament to version 4.12.0 or 5.7.0. Prioritize instances where app-based MFA is used and recovery codes are enabled.