THREAT OPS › Threat News › [GHSA] GHSA-52xp-w8hr-xv3c (high) — Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
[GHSA] GHSA-52xp-w8hr-xv3c (high) — Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
GHSA-52xp-w8hr-xv3c Severity: high CVE: CVE-2026-77567
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
A flaw in the challenge handling for app-based multi-factor authentication allows the second factor to be bypassed. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled.
MITRE ATT&CK techniques
- Multi-Factor AuthenticationT1556.006
Indicators of compromise
- CVE-2026-77567cve
Original source: https://github.com/advisories/GHSA-52xp-w8hr-xv3c