SBA Research disclosed CVE-2026-42547, an incorrect authorization flaw in DFIR-IRIS that affects versions up to 2.4.27 and allows users with alert creation or alert-writing privileges to falsely attribute alerts to customers they are not assigned to. Researchers found that a user could create an alert for an authorized customer and then modify the alert_customer_id during an update, bypassing intended tenant boundaries because the application did not properly validate authorization on security-sensitive alert properties.
The flaw was fixed in DFIR-IRIS 2.4.28, and the advisory urges organizations to upgrade immediately and enforce authorization checks on alert updates. SBA Research said the issue could also be chained with cross-site scripting to trick privileged users into reassigning alerts, potentially enabling unauthorized access to or exfiltration of alerts belonging to other customers; the issue was published after unsuccessful attempts to contact the vendor.
See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
SBA Research's GitHub advisory made public technical details of the DFIR-IRIS flaw, including the alert_customer_id manipulation path and the note that vendor contact attempts were unsuccessful. The repository states the issue was publicly disclosed on this date.
SBA Research disclosed a medium-severity incorrect authorization vulnerability in DFIR-IRIS, tracked as CVE-2026-42547. The advisory described how attackers could falsify alert attribution across customers and potentially combine the issue with cross-site scripting to exfiltrate unauthorized alerts.
DFIR-IRIS remediated CVE-2026-42547 in version 2.4.28. The flaw affected versions up to 2.4.27 and allowed users with alert-writing privileges to create or reassign alerts to customers not assigned to them.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.