Medium severity6.5NVD Advisory· Published Sep 16, 2026
CVE-2026-92605
CVE-2026-92605
Description
IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/dfir-iris/iris-web/blob/v2.4.29/source/app/blueprints/case/case_notes_routes.pynvd
- github.com/dfir-iris/iris-web/blob/v2.4.29/source/app/datamgmt/case/case_comments.pynvd
- github.com/geo-chen/oss/blob/main/iris-web.mdnvd
- www.vulncheck.com/advisories/iris-through-2.4.29-unauthorized-comment-access-via-object-idnvd
News mentions
0No linked articles in our index yet.