Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresses. The impact is limited to disclosing whether an account exists for a given email. This vulnerability is fixed in 4.11.5 and 5.6.5.
References
Configurations
No configuration.
History
22 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-22 22:16
Updated : 2026-06-23 15:03
NVD link : CVE-2026-48166
Mitre link : CVE-2026-48166
CVE.ORG link : CVE-2026-48166
JSON object : View
Products Affected
No product.
CWE
CWE-208
Observable Timing Discrepancy
