Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-306"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104181.json"
}{
"extracted_events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.13.2"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.8.2"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}