Floragasse 7 – 5th floor, 1040 Vienna

News

SBA Security Advisory – DFIR-IRIS Excessive Data Exposure (CVE-2026-42439)

Vulnerability Overview

The IRIS web application returns sensitive data to the user which are not required for the client’s operation.

  • Type of Vulnerability: Excessive Data Exposure
  • Fixed in Version: v2.4.28
  • CVE ID: CVE-2026-42539
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • CVSS Base Score: 6.5 (Medium)

Recommended Countermeasure

We recommend updating to IRIS version 2.4.28 or later.

Link

Full Security Advisory

Credits

Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)

The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.