SBA Research publicly disclosed four vulnerabilities affecting DFIR-IRIS 2.4.26 and possibly other versions, including three stored cross-site scripting flaws—CVE-2026-16969, CVE-2026-18360, and CVE-2026-18361—and an insufficient logout implementation tracked as CVE-2026-16970. The stored XSS issues affect the assets, custom attributes, and datastore upload functions, allowing attacker-supplied JavaScript to run in a victim's browser. If an administrator is targeted, the impact could extend to session hijacking or broader application compromise. The XSS issues were assigned a CVSS 3.1 score of 7.6, while the logout flaw received a 4.2 rating.
The logout weakness leaves a stolen session cookie valid after a user signs out because the application removes the cookie only on the client side and does not invalidate the session server-side, enabling continued access to protected resources. At the time of disclosure, no fix was available, and SBA Research said repeated attempts to contact the vendor were unsuccessful before publishing the advisories. Recommended mitigations include stronger output encoding, safer templating practices, serving uploaded SVG files as attachments, tightening the Content Security Policy by removing unsafe-inline, and ensuring server-side session invalidation on logout.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
SBA Research publicly disclosed CVE-2026-16970, an insufficient logout implementation issue in DFIR-IRIS 2.4.26 and possibly other versions. The flaw leaves a stolen session cookie valid after logout because the server does not invalidate the session, and no fix was available at the time of publication.
SBA Research publicly disclosed three stored cross-site scripting flaws in DFIR-IRIS 2.4.26 and possibly other versions, tracked as CVE-2026-16969, CVE-2026-18360, and CVE-2026-18361. The advisory said no fix was available at disclosure time and that prior vendor contact attempts had gone unanswered.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcecheatsheetseries.owasp.org
Open sourcedocs.dfir-iris.org
Open sourceraw.githubusercontent.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.