Stored Cross-Site Scripting Vulnerability in IRIS Web Application by SBA Research
CVE-2026-18361

7.6HIGH

Key Information:

Vendor

Dfir-iris

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-18361?

The IRIS web application exhibits a vulnerability that allows for stored cross-site scripting (XSS) attacks through improper handling of user input in the datastore upload function. This vulnerability enables an attacker to inject malicious scripts, which are then stored and executed when other users access the affected functionalities. Users of version 2.4.26 and possibly earlier versions should take immediate action to mitigate potential exploitation risks associated with this vulnerability.

Affected Version(s)

iris-web 2.4.26

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)
.