MEDIUM
CVE-2026-92605
CVSS
6.5
Description
IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.31%
Probability of exploitation in next 30 days
24.2th percentile
References
https://github.com/dfir-iris/iris-web
https://github.com/dfir-iris/iris-web/blob/v2.4.29/source/app/blueprints/case/case_notes_routes.py#L404-L411
https://github.com/dfir-iris/iris-web/blob/v2.4.29/source/app/datamgmt/case/case_comments.py#L22
https://github.com/geo-chen/oss/blob/main/iris-web.md
https://www.vulncheck.com/advisories/iris-through-2.4.29-unauthorized-comment-access-via-object-id
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.