PT-2026-45660 · Elabftw · Elabftw

Nik-Gfp

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-28511

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions eLabFTW versions prior to 5.4.2
Description An authenticated user can perform a numeric reference or search that returns results including resources they are not authorized to view. This issue allows for the unauthorized disclosure of sensitive information, such as project names or patient identifiers, if such data is included in resource titles. The exposure is limited to the title only, as authorization checks continue to block access to the actual content of the protected resources.
Recommendations Update to version 5.4.2.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-28511

Affected Products

Elabftw