CVE-2026-16970
4.2
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dfir-iris | iris-web | 2.4.26 | affected |
Weaknesses
- CWE-613: CWE-613 Insufficient session expiration
ADP Enrichment
CVE Program Container
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.