Improper Restriction of Excessive Authentication Attempts in eLabFTW - #VU137346
Published: July 12, 2026
Vulnerability details
The vulnerability allows a remote user to guess another user's password without being affected by account lockout restrictions.
The vulnerability exists due to improper restriction of excessive authentication attempts in device token-based authentication handling when validating login attempts. A remote user can use an unbound device token while attempting passwords for another account to guess another user's password without being affected by account lockout restrictions.