Junglewise Threat Intelligence

CVE-2026-18361: DFIR-IRIS IRIS Web Stored XSS in datastore upload function

CVE-2026-18361 · Severity: high · CVSS 7.6 · Published 2026-07-30

Executive brief

The IRIS web application, a platform used for incident response and digital forensics, contains a security flaw in its datastore upload feature. An attacker with basic user access can upload malicious files that execute scripts in the browsers of other users, including administrators. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of legitimate users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the IRIS web application (specifically version 2.4.26) within the datastore upload function. The application fails to properly neutralize user-supplied input during the file upload process, allowing an attacker to inject malicious scripts. This vulnerability is triggered when a victim views the uploaded content. An attacker requires low-level authenticated access to exploit this flaw. Successful exploitation can lead to session hijacking, sensitive data exposure, or unauthorized administrative actions due to the 'Scope: Changed' (S:C) nature of the vulnerability.

Affected products

  • DFIR-IRIS IRIS web application 2.4.26

Timeline

  • 2026-07-30: disclosed: Initial NVD publication date
  • 2026-07-30: advisory: SBA Research advisory published

References

Related threats