PT-2026-45660 · Elabftw · Elabftw

·

CVE-2026-28511

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions eLabFTW versions prior to 5.4.2
Description An authenticated user can perform a numeric reference or search that returns results including resources they are not authorized to view. This issue allows for the unauthorized disclosure of sensitive information, such as project names or patient identifiers, if such data is included in resource titles. The exposure is limited to the title only, as authorization checks continue to block access to the actual content of the protected resources.
Recommendations Update to version 5.4.2.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28511
GHSA-WM4R-P2JG-2MJ3

Affected Products

Elabftw