SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77567

HIGH · CVSS 8.1 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Prior to versions 4.12.0 and 5.7.0, Filament's handling of required fields in challenge forms for multi-factor authentication is flawed, allowing attackers to bypass app-based multi-factor authentication when recovery codes are enabled. This vulnerability poses a significant risk to applications utilizing Filament for Laravel development, particularly those relying on app-based authentication methods. Developers and organizations using affected versions should prioritize upgrading to the patched versions to mitigate potential security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77567
Severity
HIGH
CVSS
8.1
EPSS
0.30%

Original NVD Description

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.