


Perceptive Security
SOC/SIEM Consultancy

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 13:01:51
Source:
nvd.nist.gov
Web Technologies, Security Tools
The IRIS web application, a DFIR (Digital Forensics and Incident Response) platform, version 2.4.26 and possibly other versions, contains a stored cross-site scripting (XSS) vulnerability in its datastore upload function. This vulnerability allows attackers to inject malicious scripts that are persistently stored and executed in the context of other users' browsers. Stored XSS vulnerabilities are particularly dangerous as they do not require social engineering to trigger once the payload is in place. The vulnerability was discovered and disclosed by SBA Research, as referenced in the GitHub advisory. This affects security teams and organizations relying on IRIS for incident response workflows. Exploitation could lead to session hijacking, credential theft, or further compromise of the DFIR platform itself. The CVE was assigned as CVE-2026-18361 and is tracked on the NVD.
Technical details
Mitigation steps:
Affected products:
DFIR IRIS 2.4.26
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18361
https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
