CVE-2026-42329

MEDIUM

IRIS <2.4.28 - Open Redirect

Title source: manual
STIX 2.1

Description

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 contain a weakness where an attacker can misuse it to redirect the user to a malicious website controlled by an attacker. Version 2.4.28 fixes the issue.

References (2)

Core 2

Scores

CVSS v3 4.7
EPSS 0.0017
EPSS Percentile 7.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-602
Status published
Products (1)
dfir-iris/iris-web < 2.4.28
Published Jun 04, 2026
Tracked Since Jun 05, 2026