File Management Vulnerability in Iris Web Collaborative Platform by DFIR-IRIS
CVE-2026-22783
What is CVE-2026-22783?
The Iris web collaborative platform contains a vulnerability in its datastore file management system prior to version 2.4.24. This issue allows authenticated users to exploit the mass assignment feature of the file_local_name field, combined with untrusted path handling during deletion operations. An attacker can upload a file to the datastore, manipulate the file_local_name to reference an arbitrary filesystem path, and then execute a delete operation, resulting in unauthorized deletions of files. This critical flaw underscores the necessity for stringent input validation and path management to prevent potential abuse.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
iris-web < 2.4.24
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
