CVE-2026-28510 Details
Description
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an attacker-controlled TOTP secret and bypass the additional factor. This could result in unauthorized account access. This issue is fixed in version 5.4.2.
A vulnerability in eLabFTW, an open-source electronic lab notebook, allows for bypassing multi-factor authentication (MFA) under certain conditions. In versions through 5.4.1, the login process did not consistently maintain the MFA state across different authentication steps. This flaw enabled an attacker with valid primary credentials to complete the login process using a manipulated TOTP secret, thereby circumventing the additional authentication factor and gaining unauthorized access to the account.
Users are advised to upgrade to eLabFTW version 5.4.2. As a temporary measure, rotate credentials for affected accounts and monitor authentication events closely.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/elabftw/elabftw/commit/8b7a575aef128870861187eaa2b2f0f08654ecf9 | [email protected] | Patch |
| https://github.com/elabftw/elabftw/security/advisories/GHSA-x5wv-c9q4-fj65 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-302 | Authentication Bypass by Assumed-Immutable Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elabftw elabftw | < 5.4.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | Initial Analysis | [email protected] |
| May 5, 2026 | New CVE Received | [email protected] |