highCVSS 8.1Vulnerability

CVE-2026-77567

A flaw in the challenge handling for app-based multi-factor authentication allows the second factor to be bypassed. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled.

Properties

ghsa_id
GHSA-52xp-w8hr-xv3c
severity
high
summary
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
cvss_score
8.1
cve_id
CVE-2026-77567
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
false
ghsa_published
2026-09-01T21:28:47Z
source_url
https://github.com/advisories/GHSA-52xp-w8hr-xv3c
ghsa_updated
2026-09-01T21:28:48Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]composer/filament/filament

AFFECTS (1)

[Software]composer/filament/filament

HAS_WEAKNESS (1)

[Weakness]Improper Authentication

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77567 (CVSS 8.1) — Ninja Signal Threat Intelligence | Ninja Signal