Description
IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access. | |
| Title | IRIS through 2.4.29 Unauthorized Comment Access via Object ID | |
| First Time appeared |
Dfir-iris
Dfir-iris iris |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:dfir-iris:iris:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dfir-iris
Dfir-iris iris |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T17:31:36.375Z
Reserved: 2026-09-16T13:48:49.971Z
Link: CVE-2026-92605
No data.
Status : Received
Published: 2026-09-16T18:17:22.243
Modified: 2026-09-16T18:17:22.243
Link: CVE-2026-92605
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-639
Authorization Bypass Through User-Controlled Key