File Management Vulnerability in Iris Web Collaborative Platform by DFIR-IRIS
CVE-2026-22783

9.6CRITICAL

Key Information:

Vendor

Dfir-iris

Status
Vendor
CVE Published:
12 January 2026

What is CVE-2026-22783?

The Iris web collaborative platform contains a vulnerability in its datastore file management system prior to version 2.4.24. This issue allows authenticated users to exploit the mass assignment feature of the file_local_name field, combined with untrusted path handling during deletion operations. An attacker can upload a file to the datastore, manipulate the file_local_name to reference an arbitrary filesystem path, and then execute a delete operation, resulting in unauthorized deletions of files. This critical flaw underscores the necessity for stringent input validation and path management to prevent potential abuse.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

iris-web < 2.4.24

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.