SBA Security Advisory – DFIR-IRIS Cross-Site Request Forgery (CSRF) (CVE-2026-42543)
Vulnerability Overview
The IRIS web application is vulnerable to a Cross-site request forgery attack, because it uses the HTTP method GET to change state on the server.
- Type of Vulnerability: Cross-site request forgery (CSRF)
- Fixed in Version: v2.4.28
- CVE ID: CVE-2026-42543
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- CVSS Base Score: 4.3 (Medium)
Recommended Countermeasure
We recommend updating to IRIS version 2.4.28 or later.
Link
Credits
Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
