top of page
perceptive_background_267k.jpg

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 17:11:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Security Tools

CVE-2026-18361 affects the IRIS web application (version 2.4.26 and possibly others), exposing it to stored cross-site scripting (XSS) via the datastore upload function. Stored XSS vulnerabilities allow attackers to inject malicious scripts that are persistently saved on the server and executed in victims' browsers upon access. IRIS is a widely used DFIR (Digital Forensics and Incident Response) collaborative platform, making this vulnerability particularly sensitive given its typical deployment in security operations environments. The flaw was discovered and disclosed by SBA Research, with a detailed advisory published on their GitHub repository. Exploitation could allow attackers to hijack sessions, steal credentials, or perform actions on behalf of authenticated users. Organizations using IRIS 2.4.26 should review the advisory and apply any available patches or mitigations promptly. The vulnerability's presence in a security tooling platform amplifies its potential impact.

Technical details

Mitigation steps:

Affected products:

DFIR-IRIS 2.4.26

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page