EIP-2026-100832
PRE-CVEIris ID IrisAccess ICU 7000-2 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100832. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates multiple reflected XSS vulnerabilities via the 'HidChannelID' and 'HidVerForPHP' POST parameters in 'SetSmarcardSettings.php', as well as a CSRF vulnerability allowing administrative actions without proper validation.
Description
Iris ID IrisAccess ICU 7000-2 - Multiple Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · textwebappscgi
https://www.exploit-db.com/exploits/40165
The exploit demonstrates multiple reflected XSS vulnerabilities via the 'HidChannelID' and 'HidVerForPHP' POST parameters in 'SetSmarcardSettings.php', as well as a CSRF vulnerability allowing administrative actions without proper validation.
Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Iris ID IrisAccess ICU 7000-2 (ICU Software: 1.00.08, ICU OS: 1.3.8, EIF Firmware: 1.9, Iris TwoPi: 1.4.5)
No auth needed
Prerequisites:
Network access to the vulnerable application · User interaction for XSS (e.g., clicking a malicious link)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026