Junglewise Threat Intelligence

CVE-2026-92605: IRIS unauthorized comment enumeration via case access

CVE-2026-92605 · Severity: medium · CVSS 6.5 · Published 2026-09-16

Executive brief

IRIS is a collaborative incident response platform used by security teams to manage and document security investigations. Through version 2.4.29, the platform fails to properly check case authorization on comment listing endpoints, allowing attackers with access to any case to enumerate and read private comments from cases they are not authorized to access. This could expose sensitive investigation details and evidence to unauthorized personnel.

Technical details

The vulnerability is an authorization bypass in the comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. The root cause is insufficient case-level authorization validation before returning comment threads. An attacker with valid access to any single case can enumerate sequential object identifiers and bypass authorization checks to retrieve comment data from other cases. The attack requires authentication and network access to the IRIS instance, but does not require elevated privileges beyond basic case access. The vulnerability allows unauthorized information disclosure of sensitive incident response data. A patch addressing this authorization validation gap is expected in a version after 2.4.29.

Affected products

  • DFIR IRIS IRIS through 2.4.29

Timeline

  • 2026-09-16: disclosed

References

Related threats