CVE-2026-42543CWE-650
IRIS has a Cross-Site Request Forgery (CSRF) issue
Medium · published June 4, 2026
What it is
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request forgery attack, because they use the HTTP method `GET` to change state on the server. Version 2.4.28 contains a patch.
The record
Technical detail
- CVSS v3.1
- 4.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00174 · 7.0th percentile
- Weakness
- CWE-650 · Trusting HTTP Permission Methods on the Server Side
- Published
- 2026-06-04T21:00Z
EPSS history
Timeline