Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-9163 2026-09-10

CVE-2026-9163: Critical SQL Injection in GisLab Laboratory Management System

"A pre-authentication SQL injection flaw in GIS Informatics' GisLab Laboratory Management System carries a CVSS 3.1 base score of 9.8, allowing unauthenticated network attackers full compromise of affected deployments."

A pre-authentication SQL injection flaw in GIS Informatics' GisLab Laboratory Management System carries a CVSS 3.1 base score of 9.8, allowing unauthenticated network attackers full compromise of affected deployments.

What Is It

CVE-2026-9163 is an improper neutralization of special elements used in an SQL command (CWE-89) in the GisLab Laboratory Management System from GIS Informatics. The vulnerability permits SQL injection against the application, and was reported by Türkiye's national CSIRT, USOM ([email protected]), with the CVE record published on 2026-09-10.

The assigned CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, a base score of 9.8 (CRITICAL), with an exploitability subscore of 3.9 and an impact subscore of 5.9.

Why It Matters

The vector tells the whole story: network attack vector, low attack complexity, no privileges required, and no user interaction. That combination means an unauthenticated remote attacker can reach the flaw directly, and the high confidentiality, integrity, and availability impacts mean a successful attack compromises the data and the system behind it entirely.

CISA's SSVC assessment (version 2.0.3, dated 2026-09-10) rates the technical impact as total and marks the vulnerability automatable: yes: meaning attackers can reliably script reconnaissance and exploitation at scale. The same assessment currently records exploitation as none, and there is no CISA Known Exploited Vulnerabilities entry for this CVE, so no active in-the-wild exploitation is confirmed at this time. Laboratory management systems typically hold sensitive records, which raises the practical stakes of a full-database compromise.

What's Vulnerable

All other versions are listed with a default status of unaffected. No CPE identifiers have been published for this record.

Patch Status

The version range in the advisory indicates the issue is resolved in version 1.5; releases from 1.4.03 up to 1.5 remain affected. The NVD record is in "Received" status and no separate remediation guidance or required-action deadline has been published. Operators running GisLab in the affected range should consult the USOM advisory below and upgrade to 1.5 or later.

Sources