CVE-2024-52586 is a high-severity vulnerability affecting eLabFTW versions 4.6.0 through 5.0.9, allowing an authenticated attacker to bypass the application's built-in multifactor authentication (MFA). The vulnerability has a CVSS score of 7.8 (High), indicating that a local attacker with valid credentials can achieve high confidentiality, integrity, and availability impact by circumventing MFA. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE. Users are advised to upgrade to version 5.1.9 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.6.0, < 5.1.9CPE matchmatch criteria | cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.