lowCVSS 3.7Vulnerability

CVE-2026-84307

When multi-factor authentication is enabled, the login page presents the multi-factor challenge before evaluating `canAccessPanel()`. For an account that `canAccessPanel()` denies, submitting the correct password renders the challenge while an incorrect password returns the generic failure message, allowing an unauthenticated attacker to confirm that a password is valid for that account. When email-based multi-factor authentication is used, a login code is also sent to the account holder. This issue **only** applies to accounts that both have multi-factor authentication enabled and are denied by `canAccessPanel()`. Authentication is not bypassed as the check still runs after the challenge, and no session is created.

Properties

ghsa_id
GHSA-xwpv-pqxp-5v36
severity
low
summary
Filament: Password validity disclosure for accounts denied panel access on login page
cvss_score
3.7
cve_id
CVE-2026-84307
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
false
ghsa_published
2026-09-01T21:29:00Z
source_url
https://github.com/advisories/GHSA-xwpv-pqxp-5v36
ghsa_updated
2026-09-01T21:29:01Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]composer/filament/filament

AFFECTS (1)

[Software]composer/filament/filament

HAS_WEAKNESS (1)

[Weakness]Observable Response Discrepancy

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84307 (CVSS 3.7) — Ninja Signal Threat Intelligence | Ninja Signal