CVE-2026-9163
nicheUnauthenticated SQL Injection in GIS Informatics GisLab Laboratory Management System
CVE-2026-9163 is a critical SQL injection flaw (CWE-89) in the GIS Informatics GisLab Laboratory Management System, caused by improper neutralization of special elements used in SQL commands. Per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker can trigger it over the network by sending crafted input that is incorporated into database queries, with no privileges or user interaction required. Successful exploitation could let the attacker read, modify, or delete data in the system's database, potentially exposing sensitive laboratory records and disrupting the application, as reflected by the high confidentiality, integrity, and availability impacts. Organizations running GisLab Laboratory Management System versions 1.4.03 up to, but not including, 1.5 are affected. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the vulnerability is not listed in CISA's KEV catalog.
What to do: Upgrade GisLab Laboratory Management System to version 1.5 or later, as the affected range ends before 1.5. Until upgraded, restrict network access to the application to trusted lab networks, since the flaw is exploitable remotely without credentials, and review database/application logs for unusual queries or unexpected data access. Monitor vendor and USOM advisories for updated guidance, and note there is no public proof-of-concept to validate against yet.
| GIS Informatics GisLab Laboratory Management System | all versions from 1.4.03 up to (but not including) 1.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.