PT-2026-45660 · Elabftw · Elabftw
Nik-Gfp
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-28511
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
eLabFTW versions prior to 5.4.2
Description
An authenticated user can perform a numeric reference or search that returns results including resources they are not authorized to view. This issue allows for the unauthorized disclosure of sensitive information, such as project names or patient identifiers, if such data is included in resource titles. The exposure is limited to the title only, as authorization checks continue to block access to the actual content of the protected resources.
Recommendations
Update to version 5.4.2.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elabftw