IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access. | |
| Title | IRIS through 2.4.29 Unauthorized Comment Access via Object ID | |
| First Time appeared |
Dfir-iris
Dfir-iris iris |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:dfir-iris:iris:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dfir-iris
Dfir-iris iris |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T17:31:36.375Z
Reserved: 2026-09-16T13:48:49.971Z
Link: CVE-2026-92605
No data.
Status : Received
Published: 2026-09-16T18:17:22.243
Modified: 2026-09-16T18:17:22.243
Link: CVE-2026-92605
No data.
OpenCVE Enrichment
No data.
Weaknesses