CVE-2026-6903 affects the LabOne Web Server component, which provides the user interface for Zurich Instruments LabOne software. The vulnerability stems from insufficient input validation in file access functionality combined with inadequate cross-origin request restrictions. An unauthenticated remote attacker could exploit these flaws to read arbitrary files accessible to the operating system user running LabOne, either directly or by tricking a victim into visiting a malicious website. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily accessible to remote adversaries. The attack has high confidentiality impact as sensitive files could be disclosed, though integrity and availability are not affected. The vulnerability is only exploitable when the LabOne Web Server is actively running; users relying solely on LabOne APIs are not at risk. Currently, there is no evidence of active exploitation, with the vulnerability absent from the Known Exploited Vulnerabilities catalog. The EPSS score of 0.00025 indicates very low probability of exploitation in the wild relative to other CVEs. However, the moderate FAUCET Risk Score of 48.0/100 and the straightforward nature of the attack suggest organizations running the LabOne Web Server should prioritize patching once updates become available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Zurich Instruments | LabOne | >= 0, < 26.01.3.9CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.