ZeroHour

CVE-2026-9166

niche

Path Traversal in GIS Informatics GisLab Laboratory Management System

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-9166 is a path traversal flaw (CWE-22) in GIS Informatics GisLab Laboratory Management System, in which pathname input is not properly restricted to a designated directory. It is remotely exploitable and unauthenticated per the CVSS vector (AV:N/AC:L/PR:N/UI:N), meaning an attacker can send crafted requests containing directory-traversal sequences to an exposed instance without any credentials or user interaction. A successful attack allows the attacker to read files outside the intended directory on the server (CVSS confidentiality impact rated High, with no integrity or availability impact), which could expose configuration files, credentials, or other sensitive local data. All GisLab Laboratory Management System versions from 1.4.03 up to but not including 1.5 are affected. No public proof-of-concept is known, the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported to date.

What to do: Upgrade GisLab Laboratory Management System to version 1.5 or later, which resolves the flaw. Where upgrading is not immediately possible, limit network access to the system (e.g., restrict to trusted lab networks or place it behind a VPN) and review web/access logs for unauthenticated requests containing directory-traversal patterns such as '../'.

Affected
GIS Informatics GisLab Laboratory Management Systemfrom 1.4.03 before 1.5
Estimated exposure
nichelikely tens to hundreds of laboratory deployments (no published install-base data) — GisLab is a specialized laboratory management system from a niche vendor with no public installation or user statistics, and lab-management software is typically deployed per laboratory site, so exposure is inferred from those deployment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.