# CVE-2026-42543

## Summary

- **CVE ID:** CVE-2026-42543
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
- **CWE:** CWE-650
- **Published:** Jun 4, 2026
- **Last Modified:** Jun 8, 2026

## Description

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request forgery attack, because they use the HTTP method `GET` to change state on the server. Version 2.4.28 contains a patch.

## Affected Products

- dfir-iris — iris-web (< 2.4.28)

## References

- [CNA](https://github.com/dfir-iris/iris-web/security/advisories/GHSA-m73w-v4r5-vw9m)
- [CVE](http://www.openwall.com/lists/oss-security/2026/05/19/11)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 7.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._