CVE-2026-22783 is a high-severity vulnerability affecting DFIR-IRIS versions prior to 2.4.24, a web collaborative platform for incident responders. Authenticated users can exploit a mass assignment flaw in the file management system to delete arbitrary files on the underlying filesystem. This is achieved by uploading a file, manipulating its local name to point to a target path, and then triggering a delete operation without proper path validation. The vulnerability carries a CVSS score of 8.1 (HIGH), indicating a network-based attack with low privileges required and no user interaction, leading to high impact on integrity and availability. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. However, the vulnerability has garnered significant community discussion, with 11 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.24CPE matchmatch criteria | cpe:2.3:a:dfir-iris:iris:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.