CVE-2026-28510
Awaiting Analysis
Awaiting Analysis - Queue
eLabFTW MFA Bypass via TOTP Secret Manipulation
Publication date: 2026-05-05
Last updated on: 2026-05-07
Assigner: GitHub, Inc.
Description
Description
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an attacker-controlled TOTP secret and bypass the additional factor. This could result in unauthorized account access. This issue is fixed in version 5.4.2.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| elabftw | elabftw | to 5.4.2 (exc) |
| elabftw | elabftw | 5.4.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-302 | The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker. |