SB2026052549 - Multiple vulnerabilities in eLabFTW



SB2026052549 - Multiple vulnerabilities in eLabFTW

Published: May 25, 2026 Updated: July 12, 2026

Security Bulletin ID SB2026052549
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Authentication Bypass by Assumed-Immutable Data (CVE-ID: CVE-2026-28510)

CWE-ID: CWE-302 - Authentication Bypass by Assumed-Immutable Data

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass multi-factor authentication and gain unauthorized account access.

The vulnerability exists due to authentication bypass by assumed-immutable data in the login flow when processing attacker-controlled TOTP secret data. A remote privileged user can use valid primary credentials and complete authentication without the additional factor to bypass multi-factor authentication and gain unauthorized account access.

Multi-factor authentication may not be enforced even when enabled under certain conditions.


2) Information disclosure (CVE-ID: CVE-2026-28511)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in autocompletion search when performing a numeric reference/search. A remote user can submit a numeric search query to disclose sensitive information.

The exposed information is limited to resource titles, and direct access to the underlying protected content remains blocked by authorization checks.


Remediation

Install update from vendor's website.