THREAT OPS › Threat News › [GHSA] GHSA-r3j6-gpjw-qfjr (medium) — Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
[GHSA] GHSA-r3j6-gpjw-qfjr (medium) — Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
GHSA-r3j6-gpjw-qfjr Severity: medium CVE: CVE-2026-84306
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
A flaw in the handling of one-time codes for app-based multi-factor authentication allows a previously issued code to be used after a newer code has already been accepted. This issue does not affect email-based MFA. Submitting the exact sam
MITRE ATT&CK techniques
- Multi-Factor AuthenticationT1556.006
Indicators of compromise
- CVE-2026-84306cve
Original source: https://github.com/advisories/GHSA-r3j6-gpjw-qfjr