MEDIUM

CVE-2026-92605

2026-09-16 CVSS v3.1
CVSS
6.5

Description

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.31%
Probability of exploitation in next 30 days
24.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE