CVE-2026-48067 Details
Description
Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and AssociateAction. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value. This vulnerability is fixed in filament/actions 4.11.4 and 5.6.4 and filament/tables 3.3.51.
A vulnerability exists in Filament components for Laravel, specifically in versions 4.0.0 prior to 4.11.4, 5.6.4, and in Filament Tables versions 3.0.0 prior to 3.3.51. The issue arises in the AttachAction and AssociateAction Select fields, where the recordSelectOptionsQuery() method can be used to limit available options. However, the validation rule for these fields does not reflect the same limitations, allowing users to manipulate the state of the Livewire component and submit values outside the intended scope.
Users can update to Filament Actions versions 4.11.4 or 5.6.4, and Filament Tables version 3.3.51 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 22, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/filamentphp/filament/security/advisories/GHSA-7q3w-xqjw-g3cr | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Filament Actions | >= 4.0.0, < 4.11.3 (semver) >= 5.0.0, < 5.6.3 (semver) |
CPE
Remediation
| |
| Filament Tables | >= 3.0.0, < 3.3.50 (semver) >= 3.3.51 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |
Volerion