Login & Authentication
Forgot password
Click Forgot your password? on the login page. Enter your email address and a reset link will be sent. The link expires after a short period, so use it promptly.
If you do not receive the email, check your spam folder and ask your administrator to check email delivery. Air-Gap Workstation shows a local recovery link instead. See Password Recovery.
2FA lockout
Use one of the backup codes saved during setup. Each code works once. User Management does not provide an administrator 2FA reset.
"Invalid credentials" but password is correct
A few things to check:
- Enter the email registered to your account in the Email field
- Check if Caps Lock is on
- If your account was created via LDAP or SSO, use the corresponding login method instead of the local login form
- Your account may have been disabled by an administrator. Contact your admin to verify.
Session expired
Sessions have a limited lifetime. If you get logged out unexpectedly, simply log in again. If this happens frequently, it could be a configuration issue with your reverse proxy not forwarding cookies correctly, or a clock sync issue between your browser and the server.
Maximum sessions reached
Each user can have at most 2 concurrent sessions. When the limit is reached, the login page shows existing sessions and asks you to disconnect one before continuing. Choose the session you no longer need; Vulnotes does not automatically disconnect the oldest one.
