Junglewise Threat Intelligence

CVE-2026-28510: eLabFTW authentication bypass in MFA login flow

CVE-2026-28510 · Severity: medium · CVSS 5.9 · Published 2026-05-05

Executive brief

eLabFTW is an open-source electronic lab notebook used by researchers to manage experiments and data. A security flaw in the login process allows an attacker who already has a user's primary password to bypass multi-factor authentication (MFA). This could lead to unauthorized access to sensitive research data and administrative accounts.

Technical details

An authentication bypass vulnerability (CWE-302) exists in eLabFTW's login flow due to the insecure handling of multi-factor authentication (MFA) state. In affected versions, the `LoginController` incorrectly allowed the MFA secret to be provided via a request parameter if it was not found in the session. An attacker possessing valid primary credentials could exploit this by supplying their own TOTP secret during the authentication process, effectively bypassing the victim's configured MFA. This vulnerability is reachable over the network but requires high privileges (valid primary credentials) and has high attack complexity. The issue is resolved in version 5.4.2 by ensuring the MFA secret is only retrieved from secure session storage.

Affected products

  • eLabFTW eLabFTW <= 5.4.1

Timeline

  • 2026-04-29: advisory: Vendor advisory published on GitHub
  • 2026-05-05: disclosed: CVE published to NVD
  • 2026-05-05: patched: Fix released in version 5.4.2

References

Related threats