Junglewise Threat Intelligence

CVE-2026-42539: DFIR-IRIS IRIS excessive data exposure in API responses

CVE-2026-42539 · Severity: medium · CVSS 6.5 · Published 2026-06-04

Technologies: DFIR-IRIS Iris. Vendors: DFIR-IRIS.

Executive brief

IRIS is a collaborative platform used by incident responders to manage and share technical details during security investigations. A vulnerability in the platform's API allows authenticated users to view sensitive information that should be hidden, such as password hashes, multi-factor authentication (MFA) secrets, and internal server file paths. This exposure could allow a malicious user to compromise other accounts or gain deeper access to the server hosting the platform.

Technical details

An excessive data exposure vulnerability (CWE-201) exists in the IRIS web application API. When certain objects are accessed or updated via the API, the server returns JSON responses containing sensitive fields that are not required for client-side operations. Specifically, the `/manage/users/update/` and `/user/update` endpoints leak bcrypt password hashes and MFA secrets, while the Datastore file update endpoint leaks full local server storage paths. An attacker with low-privileged network access can exploit this to obtain credentials or reconnaissance data. The issue is fixed in version 2.4.28 by filtering these fields from API responses.

Affected products

  • DFIR-IRIS IRIS <= 2.4.27

Timeline

  • 2026-01-26: other: Vulnerability discovered by SBA Research
  • 2026-05-19: disclosed: Public disclosure on oss-security mailing list
  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-06-04: advisory: NVD record published

References

Related threats