CVE-2026-28510
EUVD-2026-2731105.05.2026, 13:16
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an attacker-controlled TOTP secret and bypass the additional factor. This could result in unauthorized account access. This issue is fixed in version 5.4.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elabftw | elabftw | 𝑥 < 5.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration