eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user performing a numeric reference/search can return results that include resources the requesting user is not authorized to view. The exposed information is limited (only the title). Attempts to access the underlying protected resource content remain blocked by authorization checks. Version 5.4.2 fixes the issue. # Affected Scope Cross-scope visibility of titles. No confirmed bypass of content-level access controls # Preconditions An authenticated user account No special privileges required beyond standard access # Impact This may enable unauthorized disclosure of sensitive information if confidential data is included in resource titles. Examples could include project names, patient identifiers, or other regulated information embedded in titles.
History

Wed, 03 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:*

Tue, 02 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Elabftw
Elabftw elabftw
Vendors & Products Elabftw
Elabftw elabftw

Mon, 01 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Description eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user performing a numeric reference/search can return results that include resources the requesting user is not authorized to view. The exposed information is limited (only the title). Attempts to access the underlying protected resource content remain blocked by authorization checks. Version 5.4.2 fixes the issue. # Affected Scope Cross-scope visibility of titles. No confirmed bypass of content-level access controls # Preconditions An authenticated user account No special privileges required beyond standard access # Impact This may enable unauthorized disclosure of sensitive information if confidential data is included in resource titles. Examples could include project names, patient identifiers, or other regulated information embedded in titles.
Title elabftw has entry title leakage through autocompletion search
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-02T15:55:36.029Z

Reserved: 2026-02-27T20:57:47.710Z

Link: CVE-2026-28511

cve-icon Vulnrichment

Updated: 2026-06-02T15:54:22.229Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-01T23:16:22.080

Modified: 2026-06-03T17:06:52.360

Link: CVE-2026-28511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T01:00:11Z