CVE-2026-42538

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. The application can therefore be misused to host phishing pages, amongst other things. This also creates another instance of a Cross-Site Scripting (XSS) vulnerability. Version 2.4.28 contains a patch.
Configurations

No configuration.

History

05 Jun 2026, 20:17

Type Values Removed Values Added
References () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-m624-7744-2mhf - () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-m624-7744-2mhf -

04 Jun 2026, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/19/8 -

04 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 21:16

Updated : 2026-06-17 10:48


NVD link : CVE-2026-42538

Mitre link : CVE-2026-42538

CVE.ORG link : CVE-2026-42538


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type