Improper Restriction of Excessive Authentication Attempts in eLabFTW - #VU137346

 

Improper Restriction of Excessive Authentication Attempts in eLabFTW - #VU137346

Published: July 12, 2026


Vulnerability identifier: #VU137346
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to guess another user's password without being affected by account lockout restrictions.

The vulnerability exists due to improper restriction of excessive authentication attempts in device token-based authentication handling when validating login attempts. A remote user can use an unbound device token while attempting passwords for another account to guess another user's password without being affected by account lockout restrictions.


Affected software

eLabFTW

Remediation

Install security update from vendor's website.

eLabFTW - update to 5.6.0

External References

Related Security Bulletins