VYPR

DFIR-IRIS

by Dfir Iris

CVEs (2)

  • CVE-2026-16970Jul 30, 2026
    risk 0.00cvss epss 0.00

    The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.

  • CVE-2026-18362Jul 30, 2026
    risk 0.00cvss epss 0.00

    The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.