Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84306— Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used

Quick assessment

Affected
filamentphp filament
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Filament 是一个用于加速 Laravel 开发的预构建全栈组件集合。在 4.0.0 至 4.12.6 以及 5.7.6 版本中, 中的 方法使用了由应用认证密钥(app authentication secret)和提交的 TOTP 代码共同派生的已使用代码缓存键。该实现通过“代码”而非“密钥”来隔离最近被接受的时间步长(timestep),导致在较新的代码已被使用后,先前签发的基于应用的多因素认证(MFA)代码仍可能被接受。虽然完全相同代码的重复使用已被阻止,但同一接受时间窗口内的其他代码仍然可用。 如果

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1110 · Brute Force

Affected Version Matrix 2

VendorProduct Version RangeStatus
filamentphp filament >= 4.0.0, < 4.12.6 affected
>= 5.0.0, < 5.7.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84306

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
Source: CVE Program / CVE List V5
Vulnerability Description
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode() with a used-code cache key derived from both the app authentication secret and the submitted TOTP code. This isolates the newest accepted timestep by code instead of by secret, allowing a previously issued app-based MFA code to be accepted after a newer code has already been used. Reuse of the exact same code was already prevented, but another code inside the accepted time window remained usable. An attacker who obtains the target account's password and one app-based MFA code can use that code for the remainder of the configured window, which is approximately four minutes with the default settings, even after the legitimate account holder logs in with a newer code. Email-based MFA is not affected. This issue is fixed in versions 4.12.6 and 5.7.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用捕获-重放进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
filamentphp filament >= 4.0.0, < 4.12.6 -

II. Public POCs for CVE-2026-84306

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84306

登录查看更多情报信息。

Patches & Fixes for CVE-2026-84306 (2)

Vendor Advisories for CVE-2026-84306 (1)

Vendor Pages for CVE-2026-84306 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-84306

No comments yet


Leave a comment