Information disclosure in eLabFTW - CVE-2026-28511

 

Information disclosure in eLabFTW - CVE-2026-28511

Published: July 12, 2026


Vulnerability identifier: #VU137342
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28511
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in autocompletion search when performing a numeric reference/search. A remote user can submit a numeric search query to disclose sensitive information.

The exposed information is limited to resource titles, and direct access to the underlying protected content remains blocked by authorization checks.


Affected software

eLabFTW

How to mitigate CVE-2026-28511

Install security update from vendor's website.

eLabFTW - update to 5.4.2

External References

Related Security Bulletins