Vulnerability record · CVE-2021-43834 · published 16 December 2021
CVE-2021-43834: Elabftw improper authentication vulnerability
Elabftw · Elabftw
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It impacts instances where LDAP or SAML is used for authentication instead of the (default) local password mechanism. Users should upgrade to at least version 4.2.0.
Description
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It impacts instances where LDAP or SAML is used for authentication instead of the (default) local password mechanism. Users should upgrade to at least version 4.2.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/elabftw/elabftw/releases/tag/4.2.0 | Release NotesThird Party Advisory |
| https://github.com/elabftw/elabftw/security/advisories/GHSA-98rp-gx76-33ph | Third Party Advisory |
| https://github.com/elabftw/elabftw/releases/tag/4.2.0 | Release NotesThird Party Advisory |
| https://github.com/elabftw/elabftw/security/advisories/GHSA-98rp-gx76-33ph | Third Party Advisory |
Track CVE-2021-43834 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-43834), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.