Insufficient Logout Vulnerability in IRIS Web Application by SBA Research
CVE-2026-16970
4.2MEDIUM
What is CVE-2026-16970?
The IRIS web application, specifically version 2.4.26 and potentially other versions, features a logout functionality that fails to properly terminate user sessions. Consequently, this weakness allows stolen session cookies to be exploited, providing unauthorized access to user accounts long after a user has attempted to log out.
Affected Version(s)
iris-web 2.4.26
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)
