PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48067 filamentphp CVE debrief

CVE-2026-48067 is a vulnerability in Filament, a collection of full-stack components for accelerated Laravel development. The vulnerability affects filament/actions versions 4.0.0 to 4.11.4 and 5.6.4, and filament/tables versions 3.0.0 to 3.3.51. An attacker who can trigger the AttachAction and AssociateAction could tamper with the Livewire component's state and submit an out-of-scope value due to a discrepancy between the recordSelectOptionsQuery() method and the built-in validation rule. This issue is fixed in filament/actions versions 4.11.4 and 5.6.4, and filament/tables version 3.3.51.

Vendor
filamentphp
Product
filament
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-22
Original CVE updated
2026-06-23
Advisory published
2026-06-22
Advisory updated
2026-06-23

Who should care

Developers and administrators using Filament for Laravel development should be aware of this vulnerability and take immediate action to update their dependencies to the patched versions. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM, indicating a moderate level of risk.

Technical summary

The vulnerability arises from the recordSelectOptionsQuery() method in filament/actions and filament/tables, which allows scoping of options for the Select field in AttachAction and AssociateAction. However, the built-in validation rule for these fields does not apply the same scope, enabling an attacker to submit an out-of-scope value. The issue is addressed in filament/actions versions 4.11.4 and 5.6.4, and filament/tables version 3.3.51.

Defensive priority

Apply updates to filament/actions and filament/tables to the patched versions as soon as possible. Review and monitor your application's usage of AttachAction and AssociateAction to detect potential exploitation attempts.

Recommended defensive actions

  • Update filament/actions to version 4.11.4 or later
  • Update filament/actions to version 5.6.4 or later
  • Update filament/tables to version 3.3.51 or later
  • Review application code for custom usage of recordSelectOptionsQuery() method
  • Monitor application logs for suspicious activity related to AttachAction and AssociateAction

Evidence notes

The CVE record and NVD detail provide official information about the vulnerability. The source item URL provides additional context from the NVD database. The reference to the GitHub security advisory offers further details on the vulnerability and its fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48067 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48067

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48067 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48067

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.