Multi-Factor Authentication Bypass in eLabFTW Open Source Notebook
CVE-2026-28510
5.9MEDIUM
What is CVE-2026-28510?
In eLabFTW versions prior to 5.4.2, a vulnerability exists in the login process that fails to consistently maintain multi-factor authentication (MFA) state across different authentication stages. This flaw allows an attacker with valid primary credentials to exploit the system by using a maliciously controlled Time-based One-Time Password (TOTP) secret. Consequently, the attacker could bypass the required additional authentication factor, leading to unauthorized access to user accounts.
Affected Version(s)
elabftw = 5.4.1
