Vulnerability DatabaseCVE-2026-104181

CVE-2026-104181: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-104181 is an authorization bypass vulnerability in Filament, a collection of full-stack components for accelerated Laravel development, where app-based multi-factor authentication (MFA) management actions do not consistently require confirmation of the current password. Affecting versions 4.0.0 through 4.13.2 and 5.0.0 through 5.8.2, an attacker with access to an authenticated user session can set up app-based MFA, obtain recovery codes, or disable app-based MFA without knowing the account password. The vulnerability was disclosed on September 23, 2026, and patched versions were released on September 18, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function): the MFA management actions — specifically SetUpAppAuthenticationAction, DisableAppAuthenticationAction, and RegenerateAppAuthenticationRecoveryCodesAction — did not require the user to re-enter their current password before executing sensitive security configuration changes. An attacker exploiting this vulnerability needs only an active authenticated session (low privileges required); they can then invoke these actions by supplying an existing TOTP app code or recovery code in lieu of the account password. The fix, implemented in PR #20522, adds mandatory password confirmation fields to all three affected MFA action forms across all supported locales (GitHub Advisory, Fix Commit).

Impact

An attacker with access to a victim's authenticated session can silently enroll their own authenticator app, retrieve recovery codes, disable the victim's existing app-based MFA, or regenerate recovery codes — all without knowing the account password. This can result in the legitimate user being locked out of their account (availability impact) and the attacker gaining persistent access to MFA recovery mechanisms (integrity impact). Email-based MFA is not affected, and the vulnerability does not independently enable unauthenticated sign-in, limiting its standalone severity (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.34%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to first obtain an authenticated user session (e.g., via session hijacking, XSS, or physical access), making fully automated exploitation unlikely.

Exploitation steps

  1. Gain session access: Obtain an authenticated Filament user session through session hijacking (e.g., cookie theft via XSS, network interception, or physical access to an unlocked browser).
  2. Navigate to MFA settings: Access the Filament panel's MFA management page using the victim's active session, which does not require re-authentication.
  3. Set up attacker-controlled MFA: Trigger the SetUpAppAuthenticationAction to enroll an attacker-controlled authenticator app. On vulnerable versions, this action does not prompt for the account password — only a valid TOTP code from the newly enrolled app is required.
  4. Retrieve recovery codes: After enrolling the authenticator app, invoke the recovery code retrieval action to obtain the account's recovery codes without supplying the account password.
  5. Optionally disable victim's MFA or regenerate codes: Trigger DisableAppAuthenticationAction or RegenerateAppAuthenticationRecoveryCodesAction by supplying an existing app TOTP code or recovery code, effectively locking the legitimate user out of their MFA configuration.
  6. Maintain persistence: Use the obtained recovery codes or the attacker-enrolled authenticator app to maintain access to the account even if the victim changes their password (GitHub Advisory).

Indicators of compromise

  • Logs: Filament/Laravel application logs showing MFA setup, disable, or recovery code regeneration events for a user account at unusual times or from unexpected IP addresses; multiple MFA configuration changes in a short timeframe.
  • Network: Authenticated requests to Filament MFA management endpoints (e.g., paths related to multi-factor/app/actions/set-up, disable, or regenerate-recovery-codes) originating from IP addresses inconsistent with the user's normal access patterns.
  • Application Behavior: A user reports being unexpectedly locked out of their MFA or receiving unexpected MFA enrollment notifications; recovery codes being invalidated without user action.

Mitigation and workarounds

Upgrade Filament to version 4.13.3 (for the 4.x branch) or 5.8.3 (for the 5.x branch), which add mandatory password confirmation to all app-based MFA management actions (v4.13.3 Release, v5.8.3 Release). No official configuration-based workaround is available for unpatched versions. As an interim measure, organizations should review audit logs for unauthorized MFA configuration changes and enforce strict session management controls (e.g., short session timeouts, IP binding) to reduce the risk of session hijacking.

Community reactions

The vulnerability was reported by researcher Yezper and coordinated by Filament maintainer danharrin, who published the advisory and merged the fix on September 18, 2026 (GitHub Advisory, Fix PR). No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified at this time.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management