SBA Security Advisory – DFIR-IRIS Open Redirect (CVE-2026-42329)
Vulnerability Overview
The IRIS web application contains a weakness where an attacker can misuse it to redirect the user to a malicious website controlled by an attacker.
- Type of Vulnerability: Open Redirect
- Fixed in Version: v2.4.28
- CVE ID: CVE-2026-42329
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
- CVSS Base Score: 4.7 (Medium)
Recommended Countermeasure
We recommend updating to IRIS version 2.4.28 or later.
Link
Credits
Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
