# CVE-2026-9163

## Summary

- **CVE ID:** CVE-2026-9163
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-89
- **Published:** Sep 10, 2026
- **Last Modified:** Sep 10, 2026

## Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection.

This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.

## Affected Products

- GIS Informatics — GisLab Laboratory Management System (1.4.03)

## References

- [CNA](https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1063)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._