CVE-2026-16971
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dfir-iris | iris-web | 2.4.26 | affected |
Weaknesses
- CWE-770: CWE-770 Allocation of resources without limits or throttling
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.