CVE-2024-25632
eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one team and a regular user in another. The vulnerability allows a regular user to become administrator of a team where they are a member, under a reasonable configuration. Additionally, in eLabFTW versions subsequent to v5.0.0, the vulnerability may allow an initially unauthenticated user to gain administrative privileges over an arbitrary team. The vulnerability does not affect system administrator status. Users should upgrade to version 5.1.0. System administrators are advised to turn off local user registration, saml_team_create and not allow administrators to import users into teams, unless strictly required.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- EPSS probability
- 0.40%
- CWE
- CWE-266, CWE-842
- Published
- 2024-10-01
- Last modified
- 2026-03-13
Affected products
- elabftw elabftw
Weakness type
Related vulnerabilities
- CVE-2026-81805 — WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability
- CVE-2026-15140 — A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP)....
- CVE-2026-86804 — seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
- CVE-2026-77654 — Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
- CVE-2026-85400 — TYPO3 CMS - Missing Authorization in lowlevel commands
- CVE-2026-81792 — WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privilege Escalation vulnerability
- CVE-2026-86516 — elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management
- CVE-2026-86512 — java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control