#VU127370 Authentication bypass using an alternate path or channel in eLabFTW - CVE-2024-52586
Published: December 9, 2024 / Updated: April 24, 2026
eLabFTW
elabftw
Description
The vulnerability allows a remote user to bypass multifactor authentication.
The vulnerability exists due to authentication bypass using an alternate path or channel in eLabFTW's built-in multifactor authentication mechanism when handling local authentication logins. A remote user can authenticate with a known or guessed password to bypass multifactor authentication.
This does not affect multifactor authentication performed by single sign-on services.