CVE-2026-84307
When multi-factor authentication is enabled, the login page presents the multi-factor challenge before evaluating `canAccessPanel()`. For an account that `canAccessPanel()` denies, submitting the correct password renders the challenge while an incorrect password returns the generic failure message, allowing an unauthenticated attacker to confirm that a password is valid for that account. When email-based multi-factor authentication is used, a login code is also sent to the account holder. This issue **only** applies to accounts that both have multi-factor authentication enabled and are denied by `canAccessPanel()`. Authentication is not bypassed as the check still runs after the challenge, and no session is created.
Properties
- ghsa_id
- GHSA-xwpv-pqxp-5v36
- severity
- low
- summary
- Filament: Password validity disclosure for accounts denied panel access on login page
- cvss_score
- 3.7
- cve_id
- CVE-2026-84307
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- is_ghsa_only
- false
- ghsa_published
- 2026-09-01T21:29:00Z
- source_url
- https://github.com/advisories/GHSA-xwpv-pqxp-5v36
- ghsa_updated
- 2026-09-01T21:29:01Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph