CVE-2026-42539

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user which are not required for the client’s operation. Version 2.4.28 contains a patch.
Configurations

No configuration.

History

08 Jun 2026, 17:16

Type Values Removed Values Added
References () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-g588-5gmf-p5cx - () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-g588-5gmf-p5cx -

04 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 22:16

Updated : 2026-06-08 17:16


NVD link : CVE-2026-42539

Mitre link : CVE-2026-42539

CVE.ORG link : CVE-2026-42539


JSON object : View

Products Affected

No product.

CWE
CWE-201

Insertion of Sensitive Information Into Sent Data