CVE-2026-104181: CWE-306: Missing Authentication for Critical Function in filamentphp filament
FilamentPHP versions from 4.0.0 up to but not including 4.13.3 and from 5.0.0 up to but not including 5.8.3 contain a vulnerability where app-based multi-factor authentication (MFA) management actions do not consistently require the current password. This allows an attacker with an authenticated session to modify app-based MFA settings without knowing the account password. Email-based MFA is not affected. The issue is fixed in versions 4.13.3 and 5.8.3.
AI Analysis
Technical Summary
CVE-2026-104181 describes a missing authentication requirement for critical functions in FilamentPHP's app-based MFA management. Specifically, from versions 4.0.0 until 4.13.3 and 5.0.0 until 5.8.3, an authenticated user session can set up or disable app-based MFA and obtain or regenerate recovery codes without confirming the current password. This flaw does not allow unauthenticated sign-in and does not affect email-based MFA. The vulnerability could lead to unauthorized changes in MFA settings, potentially locking out legitimate users. The issue is resolved in versions 4.13.3 and 5.8.3.
Potential Impact
An attacker with access to an authenticated user session can bypass password confirmation to modify app-based MFA settings, including setting up MFA, obtaining recovery codes, disabling MFA, and regenerating recovery codes. This could lead to unauthorized changes in account security settings and potentially lock out legitimate users. There is no impact on confidentiality or direct unauthorized sign-in, and email-based MFA remains unaffected.
Mitigation Recommendations
Upgrade to FilamentPHP versions 4.13.3 or later and 5.8.3 or later where this issue is fixed. Since this is a vulnerability in specific versions, applying these official fixes will remediate the issue.
CVE-2026-104181: CWE-306: Missing Authentication for Critical Function in filamentphp filament
Description
FilamentPHP versions from 4.0.0 up to but not including 4.13.3 and from 5.0.0 up to but not including 5.8.3 contain a vulnerability where app-based multi-factor authentication (MFA) management actions do not consistently require the current password. This allows an attacker with an authenticated session to modify app-based MFA settings without knowing the account password. Email-based MFA is not affected. The issue is fixed in versions 4.13.3 and 5.8.3.
CVSS v3.1
Score 5.4medium
Affected software
filamentphp
filament
pkg:composer/filamentphp/filamentRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104181 describes a missing authentication requirement for critical functions in FilamentPHP's app-based MFA management. Specifically, from versions 4.0.0 until 4.13.3 and 5.0.0 until 5.8.3, an authenticated user session can set up or disable app-based MFA and obtain or regenerate recovery codes without confirming the current password. This flaw does not allow unauthenticated sign-in and does not affect email-based MFA. The vulnerability could lead to unauthorized changes in MFA settings, potentially locking out legitimate users. The issue is resolved in versions 4.13.3 and 5.8.3.
Potential Impact
An attacker with access to an authenticated user session can bypass password confirmation to modify app-based MFA settings, including setting up MFA, obtaining recovery codes, disabling MFA, and regenerating recovery codes. This could lead to unauthorized changes in account security settings and potentially lock out legitimate users. There is no impact on confidentiality or direct unauthorized sign-in, and email-based MFA remains unaffected.
Mitigation Recommendations
Upgrade to FilamentPHP versions 4.13.3 or later and 5.8.3 or later where this issue is fixed. Since this is a vulnerability in specific versions, applying these official fixes will remediate the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-01T18:54:15.117Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abec329a43b0b3b89faf27c
Added to database: 10/01/2026, 20:31:37 UTC
Last enriched: 10/01/2026, 20:46:40 UTC
Last updated: 10/01/2026, 21:02:46 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.