highCVSS 8.1Vulnerability
CVE-2026-77567
A flaw in the challenge handling for app-based multi-factor authentication allows the second factor to be bypassed. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled.
Properties
- ghsa_id
- GHSA-52xp-w8hr-xv3c
- severity
- high
- summary
- Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
- cvss_score
- 8.1
- cve_id
- CVE-2026-77567
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- is_ghsa_only
- false
- ghsa_published
- 2026-09-01T21:28:47Z
- source_url
- https://github.com/advisories/GHSA-52xp-w8hr-xv3c
- ghsa_updated
- 2026-09-01T21:28:48Z
Related Entities (4)
VULNERABLE_TO (1)
←[Software]composer/filament/filament
AFFECTS (1)
→[Software]composer/filament/filament
HAS_WEAKNESS (1)
→[Weakness]Improper Authentication
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph