Junglewise Threat Intelligence

CVE-2026-9163: GIS Informatics GisLab Laboratory Management System SQL injection

CVE-2026-9163 · Severity: critical · CVSS 9.8 · Published 2026-09-10

Executive brief

GisLab Laboratory Management System is a laboratory information management platform used to organize and track lab operations and data. A SQL injection vulnerability allows unauthenticated attackers to execute arbitrary database commands, potentially exposing or modifying all laboratory data, samples, and research records stored in the system.

Technical details

This SQL injection vulnerability exists in GisLab Laboratory Management System versions 1.4.03 through 1.5, where user-supplied input is not properly sanitized before being incorporated into SQL queries. The vulnerability is reachable over the network without authentication requirements. Successful exploitation allows an attacker to read, modify, or delete arbitrary data from the underlying database, as well as potentially escalate privileges or gain code execution depending on database permissions and configuration. Patch or upgrade to version 1.5 or later.

Affected products

  • GIS Informatics GisLab Laboratory Management System 1.4.03 to before 1.5

Timeline

  • 2026-09-10: disclosed

References

Related threats