top of page
perceptive_background_267k.jpg

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 13:01:51

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Security Tools

The IRIS web application, a DFIR (Digital Forensics and Incident Response) platform, version 2.4.26 and possibly other versions, contains a stored cross-site scripting (XSS) vulnerability in its datastore upload function. This vulnerability allows attackers to inject malicious scripts that are persistently stored and executed in the context of other users' browsers. Stored XSS vulnerabilities are particularly dangerous as they do not require social engineering to trigger once the payload is in place. The vulnerability was discovered and disclosed by SBA Research, as referenced in the GitHub advisory. This affects security teams and organizations relying on IRIS for incident response workflows. Exploitation could lead to session hijacking, credential theft, or further compromise of the DFIR platform itself. The CVE was assigned as CVE-2026-18361 and is tracked on the NVD.

Technical details

Mitigation steps:

Affected products:

DFIR IRIS 2.4.26

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page