PT-2026-48811 · Packagist · Filament/Actions+1

Published

2026-06-11

·

Updated

2026-06-11

·

CVE-2026-48067

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and AssociateAction. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-48067
GHSA-7Q3W-XQJW-G3CR

Affected Products

Filament/Actions
Filament/Tables