Floragasse 7 – 5th floor, 1040 Vienna

News

SBA Security Advisory – DFIR-IRIS Insecure File Upload (CVE-2026-42538)

Vulnerability Overview

The IRIS web application does not properly validate uploaded files. It can therefore be misused to host phishing pages, amongst other things. This also creates an instance of a Cross-Site Scripting (XSS) vulnerability.

  • Type of Vulnerability: Insecure File Upload
  • Fixed in Version: v2.4.28
  • CVE ID: CVE-2026-42538
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
  • CVSS Base Score: 7.6 (High)

Recommended Countermeasure

We recommend updating to IRIS version 2.4.28 or later and checking whether malicious files have already been uploaded.

Link

Full Security Advisory

Credits

Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)

The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.