Authentication Bypass by Primary Weakness in eLabFTW - #VU137345

 

Authentication Bypass by Primary Weakness in eLabFTW - #VU137345

Published: July 12, 2026


Vulnerability identifier: #VU137345
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-305
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise multi-factor authentication enrollment for another user account.

The vulnerability exists due to authentication bypass by primary weakness in the first-time enforced MFA login flow when setting up MFA for an account that does not yet have MFA configured. A remote user can supply an attacker-controlled MFA secret during enrollment to compromise multi-factor authentication enrollment for another user account.

The issue requires knowledge of the target user's password and applies when MFA is enforced but not yet configured for the account.


Affected software

eLabFTW

Remediation

Install security update from vendor's website.

eLabFTW - update to 5.6.0

External References

Related Security Bulletins