CVE Explorer
CVE-2026-28511
eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user performing a numeric reference/search can return results that include resources the requesting user is not authorized to view. The exposed information is limited (only the title). Attempts to access the underlying protected resource content remain blocked by authorization checks. Version 5.4.2 fixes the issue.
# Affected Scope
Cross-scope visibility of titles.
No confirmed bypass
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"elabftw","vendor":"elabftw","versions":[{"status":"affected","version":"< 5.4.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ffe06a7a3a0f2fb787739ce033a4067e6f18814ac8c754006a5c23ecc04b12cc · sha256:deadbe1e25fe860c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ffe06a7a3a0f2fb787739ce033a4067e6f18814ac8c754006a5c23ecc04b12cc · sha256:deadbe1e25fe860c… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ffe06a7a3a0f2fb787739ce033a4067e6f18814ac8c754006a5c23ecc04b12cc · sha256:deadbe1e25fe860c… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/elabftw/elabftw/security/advisories/GHSA-wm4r-p2jg-2mj3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/elabftw/elabftw/security/advisories/GHSA-wm4r-p2jg-2mj3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ffe06a7a3a0f2fb787739ce033a4067e6f18814ac8c754006a5c23ecc04b12cc · sha256:deadbe1e25fe860c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.