IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users can create alerts for customers that are not assigned to them. This can be abused to falsely attribute fake alerts to customers. In combination with Cross-Site Scripting, this can also be used to exfiltrate alerts from other customers. Version 2.4.28 contains a patch.
References
Configurations
No configuration.
History
08 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-8hwq-v6vm-9grrĀ - |
04 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 22:16
Updated : 2026-06-08 16:16
NVD link : CVE-2026-42547
Mitre link : CVE-2026-42547
CVE.ORG link : CVE-2026-42547
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
