A security vulnerability in Filament, a collection of full-stack components for Laravel development, allows app-based multi-factor authentication (MFA) to be bypassed when recovery codes are enabled. The flaw stems from incorrect challenge-form required-field handling in versions prior to 4.12.0 and 5.7.0. Attackers could exploit this to circumvent MFA protections on affected applications. Email-based MFA is not impacted by this issue. The vulnerability has been assigned CVE-2026-77567 and is classified as high severity. Fixes have been released in Filament versions 4.12.0 and 5.7.0. Users are strongly advised to upgrade to the patched versions immediately. No workaround is mentioned other than upgrading.