Executive brief
A security flaw has been identified in the GisLab Laboratory Management System, a platform used for managing laboratory operations and data. An attacker with basic user access can bypass security checks by manipulating identification keys to view information they are not authorized to see. This could lead to the unauthorized exposure of sensitive laboratory records or research data.
Technical details
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) within the GisLab Laboratory Management System. It occurs when the application uses an identifier provided by the user to access a record without sufficiently verifying that the user has the necessary permissions for that specific record. An authenticated attacker can exploit this by modifying parameters (such as IDs in a URL or API request) to access data belonging to other users or the system. The vulnerability affects versions 1.4.03 through 08072026 and allows for unauthorized information disclosure (Confidentiality: High) while maintaining integrity and availability.
Affected products
- Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System 1.4.03 through 08072026
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory