Junglewise Threat Intelligence

CVE-2026-16969: DFIR-IRIS IRIS Web Stored XSS in assets function

CVE-2026-16969 · Severity: high · CVSS 7.6 · Published 2026-07-30

Executive brief

The IRIS web application, a platform used for incident response and digital forensics, contains a security vulnerability in its asset management feature. An attacker with basic user access can inject malicious scripts that will execute in the browsers of other users, including administrators, when they view the affected asset. This could lead to the theft of sensitive session information or unauthorized actions performed on behalf of legitimate users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the 'assets' function of the IRIS web application version 2.4.26. The application fails to properly neutralize user-supplied input before storing it and displaying it back to users. An authenticated attacker with low privileges can inject malicious JavaScript into asset fields. When a victim (such as an investigator or administrator) views the compromised asset, the script executes in their browser context. This can result in session hijacking or unauthorized data exfiltration. The vulnerability is tracked as CWE-79.

Affected products

  • DFIR-IRIS IRIS web application 2.4.26

Timeline

  • 2026-07-30: disclosed: NVD publication date
  • 2026-07-30: advisory: SBA Research advisory published

References

Related threats