PT-2026-93878 · Dfir Iris+1 · Iris-Web

·

CVE-2026-92605

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions IRIS versions prior to 2.4.30
Description Insufficient validation of case authorization occurs in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. An attacker with access to any single case can enumerate sequential object identifiers to read comment threads from cases for which they lack authorization.
Recommendations Update IRIS to version 2.4.30 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92605

Affected Products

Iris-Web