Information disclosure in eLabFTW - CVE-2026-28511
Published: July 12, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in autocompletion search when performing a numeric reference/search. A remote user can submit a numeric search query to disclose sensitive information.
The exposed information is limited to resource titles, and direct access to the underlying protected content remains blocked by authorization checks.