CVE-2026-42547

Source
https://cve.org/CVERecord?id=CVE-2026-42547
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42547.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42547
Aliases
  • GHSA-8hwq-v6vm-9grr
Published
2026-06-04T21:08:53Z
Modified
2026-08-12T03:51:18Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
IRIS Alerts Can be Falsely Attributed to Customers
Details

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users can create alerts for customers that are not assigned to them. This can be abused to falsely attribute fake alerts to customers. In combination with Cross-Site Scripting, this can also be used to exfiltrate alerts from other customers. Version 2.4.28 contains a patch.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42547.json"
}
References

Affected packages

Git / github.com/dfir-iris/iris-web

Affected ranges

Type
GIT
Repo
https://github.com/dfir-iris/iris-web
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.4.28"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.3.1
v1.4.2
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.1.0-beta-1
v2.1.0-beta-2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.10
v2.4.12
v2.4.13
v2.4.16
v2.4.18
v2.4.20
v2.4.21
v2.4.22
v2.4.23
v2.4.24
v2.4.25
v2.4.26
v2.4.27
v2.4.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42547.json"