The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 30 Jul 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks. | |
| Title | DFIR-IRIS Missing Brute Force Protection in OTP Validation | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sba-research
Published:
Updated: 2026-07-30T09:43:51.944Z
Reserved: 2026-07-24T08:24:42.942Z
Link: CVE-2026-16971
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses