Floragasse 7 – 5th floor, 1040 Vienna

News

SBA Security Advisory – DFIR-IRIS Stored XSS (CVE-2026-16969, CVE-2026-18360, CVE-2026-18361)

Vulnerability Overview

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions.

  • Type of Vulnerability: Stored XSS
  • Fixed in Version: not currently available
  • CVE IDCVE-2026-16969, CVE-2026-18360, CVE-2026-18361
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
  • CVSS Base Score: 7.6 (High)

Recommended Countermeasure

We are not aware of a fix yet. Please contact the vendor.

Link

Full Security Advisory

Credits

Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)

The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.