SB2026052549 - Multiple vulnerabilities in eLabFTW
Published: May 25, 2026 Updated: July 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Authentication Bypass by Assumed-Immutable Data (CVE-ID: CVE-2026-28510)
CWE-ID: CWE-302 - Authentication Bypass by Assumed-Immutable Data
CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass multi-factor authentication and gain unauthorized account access.
The vulnerability exists due to authentication bypass by assumed-immutable data in the login flow when processing attacker-controlled TOTP secret data. A remote privileged user can use valid primary credentials and complete authentication without the additional factor to bypass multi-factor authentication and gain unauthorized account access.
Multi-factor authentication may not be enforced even when enabled under certain conditions.
2) Information disclosure (CVE-ID: CVE-2026-28511)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in autocompletion search when performing a numeric reference/search. A remote user can submit a numeric search query to disclose sensitive information.
The exposed information is limited to resource titles, and direct access to the underlying protected content remains blocked by authorization checks.
Remediation
Install update from vendor's website.