Количество 2
Количество 2
CVE-2026-77567
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.
GHSA-52xp-w8hr-xv3c
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-77567 Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0. | CVSS3: 8.1 | 1% Низкий | около 1 месяца назад | |
GHSA-52xp-w8hr-xv3c Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled | CVSS3: 8.1 | 1% Низкий | 27 дней назад |
Уязвимостей на страницу