THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xwpv-pqxp-5v36 (low) — Filament: Password validity disclosure for accounts denied panel access on login page

[GHSA] GHSA-xwpv-pqxp-5v36 (low) — Filament: Password validity disclosure for accounts denied panel access on login page

medgithub_advisoriesPublished 2026-09-01

GHSA-xwpv-pqxp-5v36 Severity: low CVE: CVE-2026-84307

Filament: Password validity disclosure for accounts denied panel access on login page

When multi-factor authentication is enabled, the login page presents the multi-factor challenge before evaluating `canAccessPanel()`. For an account that `canAccessPanel()` denies, submitting the correct password renders the challenge while an incorrect pass

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xwpv-pqxp-5v36