eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an attacker-controlled TOTP secret and bypass the additional factor. This could result in unauthorized account access. This issue is fixed in version 5.4.2.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an attacker-controlled TOTP secret and bypass the additional factor. This could result in unauthorized account access. This issue is fixed in version 5.4.2. | |
| Title | elabftw allows MFA bypass during login | |
| Weaknesses | CWE-302 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-05T12:28:10.380Z
Reserved: 2026-02-27T20:57:47.709Z
Link: CVE-2026-28510
No data.
Status : Received
Published: 2026-05-05T13:16:28.667
Modified: 2026-05-05T13:16:28.667
Link: CVE-2026-28510
No data.
OpenCVE Enrichment
Updated: 2026-05-05T13:30:25Z