CVE-2026-28510
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an attacker-controlled TOTP secret and bypass the additional factor. This could result in unauthorized account access. This issue is fixed in version 5.4.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-302
- Published
- 2026-05-05
- Last modified
- 2026-05-06
Affected products
- elabftw elabftw
Weakness type
Related vulnerabilities
- CVE-2026-77508 — Weblate: Unverified REST API email changes
- CVE-2026-13267 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-5423 — Subscription Authentication Bypass via Unverified connectionParams.jwt
- CVE-2026-50528 — .NET Security Feature Bypass Vulnerability
- CVE-2026-47303 — ASP.NET Core Elevation of Privilege Vulnerability
- CVE-2026-48117 — DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-34460 — NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping