CVE-2026-42547 is an authorization flaw in DFIR-IRIS IRIS affecting versions up to and including 2.4.27. The issue arises because alert updates do not properly enforce authorization checks on security-relevant properties, specifically allowing a user with alerts_write privileges to create an alert for a customer they are authorized to access and then modify the alert_customer_id field to a different customer to whom they are not assigned. The vulnerable update path accepts the unauthorized customer reassignment as long as database constraints are satisfied. This enables false attribution of alerts to other customers and breaks tenant/customer access boundaries. The issue was fixed in IRIS version 2.4.28.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
alerts_write privileges to only trusted users, monitor for anomalous alert reassignments between customers, and reduce exposure to cross-site scripting because the advisory states XSS can amplify the issue into cross-customer alert exfiltration.Patch, then assume compromise.
alert_customer_id. Reject update requests that would violate customer-assignment access rules.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.