Junglewise Threat Intelligence

CVE-2026-8297: Gis Informatics GisLab Laboratory Management System SQL injection

CVE-2026-8297 · Severity: critical · CVSS 9.8 · Published 2026-07-17

Executive brief

A critical security vulnerability exists in the GisLab Laboratory Management System, a platform used for managing laboratory research and development operations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive research data, modification of laboratory records, or a complete shutdown of the system. This issue can be exploited remotely without requiring any user interaction or login credentials.

Technical details

An SQL injection vulnerability (CWE-89) exists in the GisLab Laboratory Management System due to improper neutralization of special elements used in SQL commands. The flaw is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing a remote attacker to execute arbitrary SQL queries against the backend database. This can result in the unauthorized retrieval of sensitive information, modification or deletion of data, and potential administrative access to the application. The vulnerability affects versions 1.4.03 through 08072026.

Affected products

  • Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System 1.4.03 through 08072026

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory: Published by TR-CERT and NVD

References