Authentication Bypass by Primary Weakness in eLabFTW - #VU137345
Published: July 12, 2026
Vulnerability details
The vulnerability allows a remote user to compromise multi-factor authentication enrollment for another user account.
The vulnerability exists due to authentication bypass by primary weakness in the first-time enforced MFA login flow when setting up MFA for an account that does not yet have MFA configured. A remote user can supply an attacker-controlled MFA secret during enrollment to compromise multi-factor authentication enrollment for another user account.
The issue requires knowledge of the target user's password and applies when MFA is enforced but not yet configured for the account.