CVE-2026-6903 Details
Description
The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated attacker could exploit this vulnerability to read arbitrary files on the host system that are accessible to the operating system user running the LabOne software. Additionally, the Web Server does not sufficiently restrict cross-origin requests, which could allow a remote attacker to trigger file access from a victim's browser by directing the victim to a malicious website. The vulnerability is only exploitable when the LabOne Web Server is running. Installations using only the LabOne APIs without starting the Web Server are not exposed.
A path traversal vulnerability has been identified in the LabOne Web Server, which supports the LabOne User Interface. This vulnerability arises from inadequate input validation in the file access feature, enabling an unauthenticated attacker to read arbitrary files on the host system that are accessible to the user under which the LabOne software is running. The issue is present in all LabOne versions prior to 26.01.3.9. Additionally, the Web Server's insufficient cross-origin request restrictions could allow a remote attacker to exploit this vulnerability through a victim's browser by directing them to a malicious website. However, this exploitation method is only possible when the LabOne Web Server is active, as installations using only the LabOne APIs without the Web Server running are not vulnerable.
Users are advised to update to LabOne version 26.01.3.9 or later. This update can be applied directly through the LabOne software or downloaded from the Zurich Instruments Download Center. For those who cannot upgrade immediately, it is recommended to limit access to the LabOne Web Server to localhost only, operate within a trusted laboratory network, and avoid storing sensitive data on the LabOne host.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 23, 2026CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.zhinst.com/support/download-center/ | [email protected] | Permission RequiredVendor |
| https://www.zhinst.com/support/security/2026/zi-sa-2026-001/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Zurich Instruments LabOne | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | New CVE Received | [email protected] |
Volerion