CVE-2026-42547 Details
Description
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users can create alerts for customers that are not assigned to them. This can be abused to falsely attribute fake alerts to customers. In combination with Cross-Site Scripting, this can also be used to exfiltrate alerts from other customers. Version 2.4.28 contains a patch.
A vulnerability exists in DFIR-IRIS versions prior to 2.4.28, allowing users to create alerts for customers not assigned to them. This could lead to false attribution of alerts. Additionally, when combined with Cross-Site Scripting, it could be used to exfiltrate alerts from other customers.
Users are advised to update to DFIR-IRIS version 2.4.28 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 4, 2026CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/dfir-iris/iris-web/security/advisories/GHSA-8hwq-v6vm-9grr | CISA-ADP | AdvisoryExploitRemedyVendor |
| http://www.openwall.com/lists/oss-security/2026/05/19/12 | CVE | Mailing List |
| https://github.com/dfir-iris/iris-web/security/advisories/GHSA-8hwq-v6vm-9grr | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DFIR-IRIS IRIS | <= 2.4.27 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | [email protected] |
| Jun 4, 2026 | CVE Modified | CVE |
Volerion