{"id":"CVE-2026-9166","title":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal.\n\nThis issue affects GisLab Laboratory Management System: from 1.4.…","summary":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal.\n\nThis issue affects GisLab Laboratory Management System: from 1.4.…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"GIS Informatics","product":"GisLab Laboratory Management System","affected":["gislab_laboratory_management_system >= 1.4.03 < 1.5"],"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:13:07.090","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9166","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1063","label":"iletisim@usom.gov.tr"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-10T12:39:53.132975Z"},"ingestedAt":"2026-09-10T12:48:46.274Z","epss":0.00335,"epssPercentile":0.26946,"slug":"CVE-2026-9166","body":"## Overview\n\nImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal.\n\nThis issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}