EXECUTIVE SUMMARY:
Multiple vulnerabilities affecting filament/filament have been identified in Filament, including a flaw that allows app-based multi-factor authentication to be bypassed when recovery codes are enabled, and an issue where previously issued multi-factor authentication codes can remain usable after a newer code has been accepted.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple vulnerabilities affecting filament/filament have been identified in Filament, including a flaw that allows app-based multi-factor authentication to be bypassed when recovery codes are enabled, and an issue where previously issued multi-factor authentication codes can remain usable after a newer code has been accepted.[emaillocker id="1283"]
CVE-2026-77567 (CVSS 8.1 — High): A flaw in the challenge handling for app-based multi-factor authentication allows the second factor to be bypassed, affecting email-based MFA is not impacted and this issue only applies when recovery codes are enabled.
CVE-2026-84306 (CVSS 6.5 — Medium): A flaw in the handling of one-time codes for app-based multi-factor authentication allows an issued code to be used after a newer code has already been accepted, affecting email-based MFA is not impacted and submitting the exact same code twice was already prevented but any other code within the accepted time window was not.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-52xp-w8hr-xv3c
https://github.com/advisories/GHSA-r3j6-gpjw-qfjr