


Perceptive Security
SOC/SIEM Consultancy

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
Published:
30 juli 2026 om 00:00:00
Alert date:
30 juli 2026 om 19:11:53
Source:
nvd.nist.gov
Web Technologies, Security Tools
CVE-2026-18361 affects the IRIS web application (version 2.4.26 and possibly others), exposing it to stored cross-site scripting (XSS) via the datastore upload function. Stored XSS vulnerabilities allow attackers to inject malicious scripts that are persistently saved on the server and executed in victims' browsers upon access. IRIS is a widely used DFIR (Digital Forensics and Incident Response) collaborative platform, making this vulnerability particularly sensitive given its typical deployment in security operations environments. The flaw was discovered and disclosed by SBA Research, with a detailed advisory published on their GitHub repository. Exploitation could allow attackers to hijack sessions, steal credentials, or perform actions on behalf of authenticated users. Organizations using IRIS 2.4.26 should review the advisory and apply any available patches or mitigations promptly. The vulnerability's presence in a security tooling platform amplifies its potential impact.
Technical details
Mitigation steps:
Affected products:
DFIR-IRIS 2.4.26
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18361
https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
