PT-2026-46385 · Iris · Iris

·

CVE-2026-42538

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions IRIS versions prior to 2.4.28
Description IRIS is a web collaborative platform for incident responders to share technical details during investigations. The application fails to properly validate uploaded files, which allows the platform to be misused for hosting phishing pages. This flaw also enables Cross-Site Scripting (XSS), a technique where malicious scripts are injected into trusted websites.
Recommendations Update to version 2.4.28.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42538
GHSA-M624-7744-2MHF

Affected Products

Iris