{"schema_version":1,"title":"DFIR-IRIS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in DFIR-IRIS: 0 in the last 7 days and 7 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-92605, was published on 16 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/dfir-iris","json_url":"https://junglewise.ai/threats/vendors/dfir-iris.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/dfir-iris","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":14,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":7,"last_365_days":14},"latest":[{"cve":"CVE-2026-92605","cvss":6.5,"epss":0.0042,"slug":"cve-2026-92605-iris-unauthorized-comment-enumeration-via-case-access","title":"IRIS unauthorized comment enumeration via case access","severity":"medium","exploited":false,"published_at":"2026-09-16T18:17:22.243+00:00","url":"https://junglewise.ai/threats/cve-2026-92605-iris-unauthorized-comment-enumeration-via-case-access"},{"cve":"CVE-2026-18362","cvss":5.9,"slug":"cve-2026-18362-dfir-iris-iris-web-missing-brute-force-protection-in","title":"DFIR-IRIS iris-web missing brute-force protection in authentication","severity":"medium","exploited":false,"published_at":"2026-07-30T10:16:36.58+00:00","url":"https://junglewise.ai/threats/cve-2026-18362-dfir-iris-iris-web-missing-brute-force-protection-in"},{"cve":"CVE-2026-18361","cvss":7.6,"slug":"cve-2026-18361-dfir-iris-iris-web-stored-xss-in-datastore-upload-function","title":"DFIR-IRIS IRIS Web Stored XSS in datastore upload function","severity":"high","exploited":false,"published_at":"2026-07-30T10:16:36.46+00:00","url":"https://junglewise.ai/threats/cve-2026-18361-dfir-iris-iris-web-stored-xss-in-datastore-upload-function"},{"cve":"CVE-2026-18360","cvss":7.6,"slug":"cve-2026-18360-dfir-iris-iris-web-stored-xss-in-custom-attributes","title":"DFIR-IRIS iris-web stored XSS in custom attributes","severity":"high","exploited":false,"published_at":"2026-07-30T10:16:36.343+00:00","url":"https://junglewise.ai/threats/cve-2026-18360-dfir-iris-iris-web-stored-xss-in-custom-attributes"},{"cve":"CVE-2026-16971","cvss":5.9,"slug":"cve-2026-16971-dfir-iris-iris-web-missing-brute-force-protection-in-mfa","title":"DFIR-IRIS IRIS-Web missing brute-force protection in MFA validation","severity":"medium","exploited":false,"published_at":"2026-07-30T10:16:36.22+00:00","url":"https://junglewise.ai/threats/cve-2026-16971-dfir-iris-iris-web-missing-brute-force-protection-in-mfa"},{"cve":"CVE-2026-16970","cvss":4.2,"slug":"cve-2026-16970-dfir-iris-iris-web-insufficient-session-expiration-in-logout","title":"DFIR-IRIS IRIS Web insufficient session expiration in logout function","severity":"medium","exploited":false,"published_at":"2026-07-30T10:16:36.1+00:00","url":"https://junglewise.ai/threats/cve-2026-16970-dfir-iris-iris-web-insufficient-session-expiration-in-logout"},{"cve":"CVE-2026-16969","cvss":7.6,"slug":"cve-2026-16969-dfir-iris-iris-web-stored-xss-in-assets-function","title":"DFIR-IRIS IRIS Web Stored XSS in assets function","severity":"high","exploited":false,"published_at":"2026-07-30T10:16:35.86+00:00","url":"https://junglewise.ai/threats/cve-2026-16969-dfir-iris-iris-web-stored-xss-in-assets-function"},{"cve":"CVE-2026-42547","cvss":5.4,"slug":"cve-2026-42547-dfir-iris-iris-incorrect-authorization-in-alert-management","title":"DFIR-IRIS IRIS incorrect authorization in alert management","severity":"medium","exploited":false,"published_at":"2026-06-04T22:16:53.917+00:00","url":"https://junglewise.ai/threats/cve-2026-42547-dfir-iris-iris-incorrect-authorization-in-alert-management"},{"cve":"CVE-2026-42543","cvss":4.3,"slug":"cve-2026-42543-dfir-iris-iris-csrf-via-http-get-in-state-changing-endpoints","title":"DFIR-IRIS IRIS CSRF via HTTP GET in state-changing endpoints","severity":"medium","exploited":false,"published_at":"2026-06-04T22:16:53.737+00:00","url":"https://junglewise.ai/threats/cve-2026-42543-dfir-iris-iris-csrf-via-http-get-in-state-changing-endpoints"},{"cve":"CVE-2026-42540","cvss":4.3,"slug":"cve-2026-42540-dfir-iris-iris-mass-assignment-in-api-requests","title":"DFIR-IRIS IRIS mass assignment in API requests","severity":"medium","exploited":false,"published_at":"2026-06-04T22:16:53.55+00:00","url":"https://junglewise.ai/threats/cve-2026-42540-dfir-iris-iris-mass-assignment-in-api-requests"},{"cve":"CVE-2026-42539","cvss":6.5,"slug":"cve-2026-42539-dfir-iris-iris-excessive-data-exposure-in-api-responses","title":"DFIR-IRIS IRIS excessive data exposure in API responses","severity":"medium","exploited":false,"published_at":"2026-06-04T22:16:53.37+00:00","url":"https://junglewise.ai/threats/cve-2026-42539-dfir-iris-iris-excessive-data-exposure-in-api-responses"},{"cve":"CVE-2026-42538","cvss":6.3,"slug":"cve-2026-42538-dfir-iris-iris-unrestricted-file-upload-and-stored-xss","title":"DFIR-IRIS IRIS unrestricted file upload and stored XSS","severity":"medium","exploited":false,"published_at":"2026-06-04T21:16:30.73+00:00","url":"https://junglewise.ai/threats/cve-2026-42538-dfir-iris-iris-unrestricted-file-upload-and-stored-xss"},{"cve":"CVE-2026-42329","cvss":4.7,"slug":"cve-2026-42329-dfir-iris-iris-open-redirect-in-login-component","title":"DFIR-IRIS Iris Open Redirect in login component","severity":"medium","exploited":false,"published_at":"2026-06-04T21:16:30.563+00:00","url":"https://junglewise.ai/threats/cve-2026-42329-dfir-iris-iris-open-redirect-in-login-component"},{"cve":"CVE-2026-41522","cvss":7.1,"slug":"cve-2026-41522-dfir-iris-improper-authorization-in-graphql-endpoint","title":"DFIR-IRIS improper authorization in GraphQL endpoint","severity":"info","exploited":false,"published_at":"2026-06-04T20:16:58.14+00:00","url":"https://junglewise.ai/threats/cve-2026-41522-dfir-iris-improper-authorization-in-graphql-endpoint"}],"vendor":{"hub":true,"name":"DFIR-IRIS","slug":"dfir-iris","homepage":"https://dfir-iris.org/","description":"An open-source project focused on digital forensics and incident response orchestration.","url":"https://junglewise.ai/threats/vendors/dfir-iris"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-18361","cvss":7.6,"slug":"cve-2026-18361-dfir-iris-iris-web-stored-xss-in-datastore-upload-function","title":"DFIR-IRIS IRIS Web Stored XSS in datastore upload function","severity":"high","exploited":false,"published_at":"2026-07-30T10:16:36.46+00:00","url":"https://junglewise.ai/threats/cve-2026-18361-dfir-iris-iris-web-stored-xss-in-datastore-upload-function"},{"cve":"CVE-2026-18360","cvss":7.6,"slug":"cve-2026-18360-dfir-iris-iris-web-stored-xss-in-custom-attributes","title":"DFIR-IRIS iris-web stored XSS in custom attributes","severity":"high","exploited":false,"published_at":"2026-07-30T10:16:36.343+00:00","url":"https://junglewise.ai/threats/cve-2026-18360-dfir-iris-iris-web-stored-xss-in-custom-attributes"},{"cve":"CVE-2026-16969","cvss":7.6,"slug":"cve-2026-16969-dfir-iris-iris-web-stored-xss-in-assets-function","title":"DFIR-IRIS IRIS Web Stored XSS in assets function","severity":"high","exploited":false,"published_at":"2026-07-30T10:16:35.86+00:00","url":"https://junglewise.ai/threats/cve-2026-16969-dfir-iris-iris-web-stored-xss-in-assets-function"},{"cve":"CVE-2026-92605","cvss":6.5,"epss":0.0042,"slug":"cve-2026-92605-iris-unauthorized-comment-enumeration-via-case-access","title":"IRIS unauthorized comment enumeration via case access","severity":"medium","exploited":false,"published_at":"2026-09-16T18:17:22.243+00:00","url":"https://junglewise.ai/threats/cve-2026-92605-iris-unauthorized-comment-enumeration-via-case-access"},{"cve":"CVE-2026-42539","cvss":6.5,"slug":"cve-2026-42539-dfir-iris-iris-excessive-data-exposure-in-api-responses","title":"DFIR-IRIS IRIS excessive data exposure in API responses","severity":"medium","exploited":false,"published_at":"2026-06-04T22:16:53.37+00:00","url":"https://junglewise.ai/threats/cve-2026-42539-dfir-iris-iris-excessive-data-exposure-in-api-responses"},{"cve":"CVE-2026-42538","cvss":6.3,"slug":"cve-2026-42538-dfir-iris-iris-unrestricted-file-upload-and-stored-xss","title":"DFIR-IRIS IRIS unrestricted file upload and stored XSS","severity":"medium","exploited":false,"published_at":"2026-06-04T21:16:30.73+00:00","url":"https://junglewise.ai/threats/cve-2026-42538-dfir-iris-iris-unrestricted-file-upload-and-stored-xss"},{"cve":"CVE-2026-18362","cvss":5.9,"slug":"cve-2026-18362-dfir-iris-iris-web-missing-brute-force-protection-in","title":"DFIR-IRIS iris-web missing brute-force protection in authentication","severity":"medium","exploited":false,"published_at":"2026-07-30T10:16:36.58+00:00","url":"https://junglewise.ai/threats/cve-2026-18362-dfir-iris-iris-web-missing-brute-force-protection-in"},{"cve":"CVE-2026-16971","cvss":5.9,"slug":"cve-2026-16971-dfir-iris-iris-web-missing-brute-force-protection-in-mfa","title":"DFIR-IRIS IRIS-Web missing brute-force protection in MFA validation","severity":"medium","exploited":false,"published_at":"2026-07-30T10:16:36.22+00:00","url":"https://junglewise.ai/threats/cve-2026-16971-dfir-iris-iris-web-missing-brute-force-protection-in-mfa"},{"cve":"CVE-2026-42547","cvss":5.4,"slug":"cve-2026-42547-dfir-iris-iris-incorrect-authorization-in-alert-management","title":"DFIR-IRIS IRIS incorrect authorization in alert management","severity":"medium","exploited":false,"published_at":"2026-06-04T22:16:53.917+00:00","url":"https://junglewise.ai/threats/cve-2026-42547-dfir-iris-iris-incorrect-authorization-in-alert-management"},{"cve":"CVE-2026-42329","cvss":4.7,"slug":"cve-2026-42329-dfir-iris-iris-open-redirect-in-login-component","title":"DFIR-IRIS Iris Open Redirect in login component","severity":"medium","exploited":false,"published_at":"2026-06-04T21:16:30.563+00:00","url":"https://junglewise.ai/threats/cve-2026-42329-dfir-iris-iris-open-redirect-in-login-component"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"DFIR-IRIS IRIS","slug":"iris","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/iris"},{"name":"DFIR-IRIS Iris-Web","slug":"iris-web","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/iris-web"}]}