PT-2026-37035 · Elabftw · Elabftw
Bryanqb07
·
Published
2026-05-05
·
Updated
2026-05-12
·
CVE-2026-28510
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
eLabFTW versions prior to 5.4.2
Description
The login flow in this open source electronic lab notebook does not reliably preserve the multi-factor authentication state across authentication steps. An attacker possessing valid primary credentials could, under certain conditions, use an attacker-controlled TOTP (Time-based One-Time Password) secret to bypass the additional authentication factor, leading to unauthorized account access.
Recommendations
Update to version 5.4.2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elabftw