Threat Advisory

Filament Vulnerabilities Allow One-Time Token Reuse Within Time Window

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting filament/filament have been identified in Filament, including a flaw that allows app-based multi-factor authentication to be bypassed when recovery codes are enabled, and an issue where previously issued multi-factor authentication codes can remain usable after a newer code has been accepted.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting filament/filament have been identified in Filament, including a flaw that allows app-based multi-factor authentication to be bypassed when recovery codes are enabled, and an issue where previously issued multi-factor authentication codes can remain usable after a newer code has been accepted.[emaillocker id="1283"]

CVE-2026-77567 (CVSS 8.1 — High): A flaw in the challenge handling for app-based multi-factor authentication allows the second factor to be bypassed, affecting email-based MFA is not impacted and this issue only applies when recovery codes are enabled.

CVE-2026-84306 (CVSS 6.5 — Medium): A flaw in the handling of one-time codes for app-based multi-factor authentication allows an issued code to be used after a newer code has already been accepted, affecting email-based MFA is not impacted and submitting the exact same code twice was already prevented but any other code within the accepted time window was not.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-52xp-w8hr-xv3c
https://github.com/advisories/GHSA-r3j6-gpjw-qfjr

[/emaillocker]
crossmenu