SBA Security Advisory – DFIR-IRIS Alerts Can be Falsely Attributed to Customers (CVE-2026-42547)
Vulnerability Overview
Users can create alerts for customers that are not assigned to them. This can be abused to falsely attribute fake alerts to customers. In combination with Cross-Site Scripting, this can also be used to exfiltrate alerts from other customers.
- Type of Vulnerability: Alerts Can be Falsely Attributed to Customers
- Fixed in Version: v2.4.28
- CVE ID: CVE-2026-42547
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- CVSS Base Score: 5.4 (Medium)
Recommended Countermeasure
We recommend updating to IRIS version 2.4.28 or later.
Link
Credits
Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
