Junglewise Threat Intelligence

CVE-2026-18362: DFIR-IRIS iris-web missing brute-force protection in authentication

CVE-2026-18362 · Severity: medium · CVSS 5.9 · Published 2026-07-30

Executive brief

The IRIS web application, a platform used for digital forensics and incident response, fails to limit the number of failed login attempts. This allows an attacker to repeatedly guess user passwords without being blocked or slowed down. If successful, an attacker could gain unauthorized access to sensitive investigation data and incident management tools.

Technical details

The IRIS web application (iris-web) version 2.4.26 is vulnerable to improper restriction of excessive authentication attempts (CWE-770). The application lacks rate limiting or account lockout mechanisms on its authentication endpoint. A remote, unauthenticated attacker can perform automated brute-force or dictionary attacks against user accounts. A successful attack results in unauthorized access to the application, potentially compromising sensitive forensic data. The vulnerability is tracked as CVE-2026-18362.

Affected products

  • dfir-iris iris-web 2.4.26

Timeline

  • 2026-07-30: advisory
  • 2026-07-30: disclosed

References

Related threats