CVE-2026-16970: Dfir-Iris Iris-Web

Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.

The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.

Affected products

Published 2026-07-30. Last modified 2026-08-04.