
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-104181 is an authorization bypass vulnerability in Filament, a collection of full-stack components for accelerated Laravel development, where app-based multi-factor authentication (MFA) management actions do not consistently require confirmation of the current password. Affecting versions 4.0.0 through 4.13.2 and 5.0.0 through 5.8.2, an attacker with access to an authenticated user session can set up app-based MFA, obtain recovery codes, or disable app-based MFA without knowing the account password. The vulnerability was disclosed on September 23, 2026, and patched versions were released on September 18, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function): the MFA management actions — specifically SetUpAppAuthenticationAction, DisableAppAuthenticationAction, and RegenerateAppAuthenticationRecoveryCodesAction — did not require the user to re-enter their current password before executing sensitive security configuration changes. An attacker exploiting this vulnerability needs only an active authenticated session (low privileges required); they can then invoke these actions by supplying an existing TOTP app code or recovery code in lieu of the account password. The fix, implemented in PR #20522, adds mandatory password confirmation fields to all three affected MFA action forms across all supported locales (GitHub Advisory, Fix Commit).
An attacker with access to a victim's authenticated session can silently enroll their own authenticator app, retrieve recovery codes, disable the victim's existing app-based MFA, or regenerate recovery codes — all without knowing the account password. This can result in the legitimate user being locked out of their account (availability impact) and the attacker gaining persistent access to MFA recovery mechanisms (integrity impact). Email-based MFA is not affected, and the vulnerability does not independently enable unauthenticated sign-in, limiting its standalone severity (GitHub Advisory).
No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.34%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to first obtain an authenticated user session (e.g., via session hijacking, XSS, or physical access), making fully automated exploitation unlikely.
SetUpAppAuthenticationAction to enroll an attacker-controlled authenticator app. On vulnerable versions, this action does not prompt for the account password — only a valid TOTP code from the newly enrolled app is required.DisableAppAuthenticationAction or RegenerateAppAuthenticationRecoveryCodesAction by supplying an existing app TOTP code or recovery code, effectively locking the legitimate user out of their MFA configuration.multi-factor/app/actions/set-up, disable, or regenerate-recovery-codes) originating from IP addresses inconsistent with the user's normal access patterns.Upgrade Filament to version 4.13.3 (for the 4.x branch) or 5.8.3 (for the 5.x branch), which add mandatory password confirmation to all app-based MFA management actions (v4.13.3 Release, v5.8.3 Release). No official configuration-based workaround is available for unpatched versions. As an interim measure, organizations should review audit logs for unauthorized MFA configuration changes and enforce strict session management controls (e.g., short session timeouts, IP binding) to reduce the risk of session hijacking.
The vulnerability was reported by researcher Yezper and coordinated by Filament maintainer danharrin, who published the advisory and merged the fix on September 18, 2026 (GitHub Advisory, Fix PR). No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."