Junglewise Threat Intelligence

CVE-2026-18360: DFIR-IRIS iris-web stored XSS in custom attributes

CVE-2026-18360 · Severity: high · CVSS 7.6 · Published 2026-07-30

Executive brief

The IRIS web application, a platform used for digital forensics and incident response, contains a security flaw in its custom attributes feature. An attacker with basic user access can inject malicious scripts that execute when other users, including administrators, view specific pages. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of legitimate users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the IRIS web application (iris-web) version 2.4.26. The flaw is located within the custom attributes function, where user-supplied input is improperly neutralized before being stored and rendered in the web interface. An authenticated attacker with low privileges can inject malicious JavaScript into these attributes. When a victim (such as an analyst or administrator) views the affected attribute, the script executes in the context of their browser session. This can result in session hijacking or unauthorized data exfiltration. The vulnerability is tracked as CVE-2026-18360.

Affected products

  • dfir-iris iris-web 2.4.26

Timeline

  • 2026-07-30: disclosed: Initial NVD publication date
  • 2026-07-30: advisory: SBA Research advisory published

References

Related threats