


Perceptive Security
SOC/SIEM Consultancy

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 11:01:51
Source:
nvd.nist.gov
Web Technologies, Security Tools
CVE-2026-18360 affects the IRIS web application version 2.4.26 and possibly other versions. The vulnerability is a stored cross-site scripting (XSS) flaw located in the custom attributes function of the application. Stored XSS allows attackers to inject malicious scripts that are persistently saved on the server and executed in the browsers of users who access the affected page. IRIS is a collaborative incident response platform used in digital forensics and incident response (DFIR) workflows. This type of vulnerability can lead to session hijacking, credential theft, or further lateral movement within an organization. The advisory was published by SBA Research and details are available on both NVD and GitHub. Organizations using IRIS should review the advisory and apply any available patches or mitigations promptly.
Technical details
Mitigation steps:
Affected products:
DFIR-IRIS 2.4.26
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18360
https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
