Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6903

25
FAUCET Score

CVE-2026-6903 affects the LabOne Web Server component, which provides the user interface for Zurich Instruments LabOne software. The vulnerability stems from insufficient input validation in file access functionality combined with inadequate cross-origin request restrictions. An unauthenticated remote attacker could exploit these flaws to read arbitrary files accessible to the operating system user running LabOne, either directly or by tricking a victim into visiting a malicious website. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily accessible to remote adversaries. The attack has high confidentiality impact as sensitive files could be disclosed, though integrity and availability are not affected. The vulnerability is only exploitable when the LabOne Web Server is actively running; users relying solely on LabOne APIs are not at risk. Currently, there is no evidence of active exploitation, with the vulnerability absent from the Known Exploited Vulnerabilities catalog. The EPSS score of 0.00025 indicates very low probability of exploitation in the wild relative to other CVEs. However, the moderate FAUCET Risk Score of 48.0/100 and the straightforward nature of the attack suggest organizations running the LabOne Web Server should prioritize patching once updates become available.

Impacted Technologies

VendorProductVersion(s)CPE
Zurich InstrumentsLabOne
>= 0, < 26.01.3.9CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
25.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 7th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

zhinst.com / support/download-center
zhinst.com / support/security/2026/zi-sa-2026-001