Insufficient Logout Vulnerability in IRIS Web Application by SBA Research
CVE-2026-16970

4.2MEDIUM

Key Information:

Vendor

Dfir-iris

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-16970?

The IRIS web application, specifically version 2.4.26 and potentially other versions, features a logout functionality that fails to properly terminate user sessions. Consequently, this weakness allows stolen session cookies to be exploited, providing unauthorized access to user accounts long after a user has attempted to log out.

Affected Version(s)

iris-web 2.4.26

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)
.