Multi-Factor Authentication Bypass in eLabFTW Open Source Notebook
CVE-2026-28510

5.9MEDIUM

Key Information:

Vendor

Elabftw

Status
Vendor
CVE Published:
5 May 2026

What is CVE-2026-28510?

In eLabFTW versions prior to 5.4.2, a vulnerability exists in the login process that fails to consistently maintain multi-factor authentication (MFA) state across different authentication stages. This flaw allows an attacker with valid primary credentials to exploit the system by using a maliciously controlled Time-based One-Time Password (TOTP) secret. Consequently, the attacker could bypass the required additional authentication factor, leading to unauthorized access to user accounts.

Affected Version(s)

elabftw = 5.4.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.