Back

HIGH

Path Traversal Vulnerability in LabOne User Interface

Published Apr 23, 2026

Description

The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated attacker could exploit this vulnerability to read arbitrary files on the host system that are accessible to the operating system user running the LabOne software.

Additionally, the Web Server does not sufficiently restrict cross-origin requests, which could allow a remote attacker to trigger file access from a victim's browser by directing the victim to a malicious website.

The vulnerability is only exploitable when the LabOne Web Server is running. Installations using only the LabOne APIs without starting the Web Server are not exposed.

Affected products

Remediation

Vendor solution

Update to LabOne 26.01.3.9 or later. The update can be applied directly through the LabOne software, or downloaded from the Zurich Instruments Download Center at https://www.zhinst.com/support/download-center.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NCSC.ch
Published Apr 23, 2026
Updated Apr 23, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated Apr 23, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner NCSC.ch
Published Apr 23, 2026
Updated Apr 23, 2026
Exploited since n/a
EUVD-2026-25215