THREAT OPS › Threat News › [GHSA] GHSA-xwpv-pqxp-5v36 (low) — Filament: Password validity disclosure for accounts denied panel access on login page
[GHSA] GHSA-xwpv-pqxp-5v36 (low) — Filament: Password validity disclosure for accounts denied panel access on login page
GHSA-xwpv-pqxp-5v36 Severity: low CVE: CVE-2026-84307
Filament: Password validity disclosure for accounts denied panel access on login page
When multi-factor authentication is enabled, the login page presents the multi-factor challenge before evaluating `canAccessPanel()`. For an account that `canAccessPanel()` denies, submitting the correct password renders the challenge while an incorrect pass
MITRE ATT&CK techniques
- Multi-Factor AuthenticationT1556.006
Indicators of compromise
- CVE-2026-84307cve
Original source: https://github.com/advisories/GHSA-xwpv-pqxp-5v36