---
id: CVE-2026-92605
title: >-
  IRIS through 2.4.29 fails to properly validate case authorization in comment
  listing endpoints for notes, tasks, IOCs, assets, and evidence items
summary: >-
  IRIS through 2.4.29 fails to properly validate case authorization in comment
  listing endpoints for notes, tasks, IOCs, assets, and evidence items.
  Attackers with access to any single case can enumerate sequential object
  identifiers and r…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: dfir-iris
product: iris-web
affected:
  - iris-web <= 2.4.29
published: '2026-09-16'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92605'
references:
  - url: 'https://github.com/dfir-iris/iris-web'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/dfir-iris/iris-web/blob/v2.4.29/source/app/blueprints/case/case_notes_routes.py#L404-L411
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/dfir-iris/iris-web/blob/v2.4.29/source/app/datamgmt/case/case_comments.py#L22
    label: disclosure@vulncheck.com
  - url: 'https://github.com/geo-chen/oss/blob/main/iris-web.md'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/iris-through-2.4.29-unauthorized-comment-access-via-object-id
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00415
epssPercentile: 0.33246
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:16:46.485633Z'
ingestedAt: '2026-09-16T18:01:17.461Z'
---

## Overview

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and read comment threads from cases they have no authorization to access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
