PT-2026-93878 · Dfir Iris+1 · Iris-Web
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
IRIS versions prior to 2.4.30
Description
Insufficient validation of case authorization occurs in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. An attacker with access to any single case can enumerate sequential object identifiers to read comment threads from cases for which they lack authorization.
Recommendations
Update IRIS to version 2.4.30 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iris-Web