top of page
perceptive_background_267k.jpg

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 11:01:51

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Security Tools

CVE-2026-16969 describes a stored cross-site scripting (XSS) vulnerability in the IRIS web application, specifically in version 2.4.26 and possibly other versions. The vulnerability exists within the assets function of the application. Stored XSS vulnerabilities allow attackers to inject malicious scripts that are persistently saved on the server and executed in the browsers of users who access the affected page. IRIS is a DFIR (Digital Forensics and Incident Response) collaborative platform, making this vulnerability particularly sensitive as it targets security professionals. The vulnerability was reported by SBA Research and published as an advisory. Exploitation could lead to session hijacking, credential theft, or further compromise of the incident response environment.

Technical details

Mitigation steps:

Affected products:

IRIS web application 2.4.26
DFIR-IRIS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page