Description
IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data disclosure via comment enumeration
Action: Patch urgently
AI Analysis

Impact

IRIS through version 2.4.29 has a flaw in the comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. The system does not properly enforce case authorization, allowing an attacker who has access to any single case to iterate through sequential object identifiers and read the comment threads of other cases for which the attacker has no legitimate permission. This results in the unauthorized disclosure of potentially sensitive information, compromising the confidentiality of remarks and evidence stored within the platform.

Affected Systems

The affected product is dfir-iris iris-web running versions up to and including 2.4.29. The vulnerability is present in any deployment of the web application that has not applied a post‑2.4.29 update.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity vulnerability; however, the EPSS score is below 1%, suggesting the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to possess the credentials or session for at least one case, after which they can enumerate object IDs and access comment data from unauthorized cases. No known public exploit has been reported, but the lack of proper authorization checks makes discovery straightforward for privileged users with access to any case.

Generated by OpenCVE AI on September 18, 2026 at 06:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade iris-web to a version newer than 2.4.29 or apply any vendor‑issued patch that corrects comment‑listing authorization checks.
  • Restrict users from ability to enumerate case identifiers by disabling or hardening sequential ID iteration in the API endpoints.
  • Implement audit logging for comment access attempts and review logs for unauthorized enumeration patterns.

Generated by OpenCVE AI on September 18, 2026 at 06:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.
Title IRIS through 2.4.29 Unauthorized Comment Access via Object ID
First Time appeared Dfir-iris
Dfir-iris iris
Weaknesses CWE-639
CPEs cpe:2.3:a:dfir-iris:iris:*:*:*:*:*:*:*:*
Vendors & Products Dfir-iris
Dfir-iris iris
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:49.562Z

Reserved: 2026-09-16T13:48:49.971Z

Link: CVE-2026-92605

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:47.691Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T18:17:22.243

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:45:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key