Incorrect Implementation of Authentication Algorithm in eLabFTW - CVE-2021-43834

 

Incorrect Implementation of Authentication Algorithm in eLabFTW - CVE-2021-43834

Published: December 15, 2021 / Updated: April 24, 2026


Vulnerability identifier: #VU127367
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43834
CWE-ID: CWE-303
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to authenticate as an existing user.

The vulnerability exists due to incorrect implementation of an authentication algorithm in the authentication mechanism when processing login attempts for accounts created with single sign-on authentication options. A remote attacker can submit crafted authentication data to authenticate as an existing user.

Only instances using LDAP or SAML authentication for affected accounts are vulnerable.


Affected software

eLabFTW

How to mitigate CVE-2021-43834

Install security update from vendor's website.

eLabFTW - update to 4.2.0

External References

Related Security Bulletins