CVE-2026-42539

MEDIUM

IRIS <2.4.28 - Excessive Data Exposure

Title source: manual
STIX 2.1

Description

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user which are not required for the client’s operation. Version 2.4.28 contains a patch.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 13.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
dfir-iris/iris-web < 2.4.28
Published Jun 04, 2026
Tracked Since Jun 05, 2026