CVE-2026-9166
nichePath Traversal in GIS Informatics GisLab Laboratory Management System
CVE-2026-9166 is a path traversal flaw (CWE-22) in GIS Informatics GisLab Laboratory Management System, in which pathname input is not properly restricted to a designated directory. It is remotely exploitable and unauthenticated per the CVSS vector (AV:N/AC:L/PR:N/UI:N), meaning an attacker can send crafted requests containing directory-traversal sequences to an exposed instance without any credentials or user interaction. A successful attack allows the attacker to read files outside the intended directory on the server (CVSS confidentiality impact rated High, with no integrity or availability impact), which could expose configuration files, credentials, or other sensitive local data. All GisLab Laboratory Management System versions from 1.4.03 up to but not including 1.5 are affected. No public proof-of-concept is known, the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported to date.
What to do: Upgrade GisLab Laboratory Management System to version 1.5 or later, which resolves the flaw. Where upgrading is not immediately possible, limit network access to the system (e.g., restrict to trusted lab networks or place it behind a VPN) and review web/access logs for unauthenticated requests containing directory-traversal patterns such as '../'.
| GIS Informatics GisLab Laboratory Management System | from 1.4.03 before 1.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.