Authentication Bypass by Assumed-Immutable Data in eLabFTW - CVE-2026-28510
Published: May 25, 2026
eLabFTW
Detailed vulnerability description
The vulnerability allows a remote user to bypass multi-factor authentication and gain unauthorized account access.
The vulnerability exists due to authentication bypass by assumed-immutable data in the login flow when processing attacker-controlled TOTP secret data. A remote privileged user can use valid primary credentials and complete authentication without the additional factor to bypass multi-factor authentication and gain unauthorized account access.
Multi-factor authentication may not be enforced even when enabled under certain conditions.