A pre-authentication SQL injection flaw in GIS Informatics' GisLab Laboratory Management System carries a CVSS 3.1 base score of 9.8, allowing unauthenticated network attackers full compromise of affected deployments.
What Is It
CVE-2026-9163 is an improper neutralization of special elements used in an SQL command (CWE-89) in the GisLab Laboratory Management System from GIS Informatics. The vulnerability permits SQL injection against the application, and was reported by Türkiye's national CSIRT, USOM ([email protected]), with the CVE record published on 2026-09-10.
The assigned CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, a base score of 9.8 (CRITICAL), with an exploitability subscore of 3.9 and an impact subscore of 5.9.
Why It Matters
The vector tells the whole story: network attack vector, low attack complexity, no privileges required, and no user interaction. That combination means an unauthenticated remote attacker can reach the flaw directly, and the high confidentiality, integrity, and availability impacts mean a successful attack compromises the data and the system behind it entirely.
CISA's SSVC assessment (version 2.0.3, dated 2026-09-10) rates the technical impact as total and marks the vulnerability automatable: yes: meaning attackers can reliably script reconnaissance and exploitation at scale. The same assessment currently records exploitation as none, and there is no CISA Known Exploited Vulnerabilities entry for this CVE, so no active in-the-wild exploitation is confirmed at this time. Laboratory management systems typically hold sensitive records, which raises the practical stakes of a full-database compromise.
What's Vulnerable
- Vendor: GIS Informatics
- Product: GisLab Laboratory Management System
- Affected versions: from 1.4.03 up to (but not including) 1.5
All other versions are listed with a default status of unaffected. No CPE identifiers have been published for this record.
Patch Status
The version range in the advisory indicates the issue is resolved in version 1.5; releases from 1.4.03 up to 1.5 remain affected. The NVD record is in "Received" status and no separate remediation guidance or required-action deadline has been published. Operators running GisLab in the affected range should consult the USOM advisory below and upgrade to 1.5 or later.
Sources
- NVD, CVE-2026-9163: https://nvd.nist.gov/vuln/detail/CVE-2026-9163
- USOM (Türkiye National Cyber Incident Response Center) Advisory TR-26-1063: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1063