CVE-2026-92605 PUBLISHED

IRIS through 2.4.29 Unauthorized Comment Access via Object ID

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor dfir-iris
Product iris-web
Versions Default: unaffected
  • affected from 0 to 2.4.29 (incl.)

Credits

  • George Chen reporter

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE