SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16971

MEDIUM · CVSS 5.9 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The IRIS web application, specifically version 2.4.26 and potentially other versions, is vulnerable due to inadequate protection of its multi-factor authentication (MFA) validation, allowing attackers to exploit this weakness through brute-force methods. This vulnerability could lead to unauthorized access to user accounts, compromising sensitive information. Organizations utilizing this application should prioritize remediation to enhance their security posture against potential brute-force attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16971
Severity
MEDIUM
CVSS
5.9
EPSS
0.22%

Original NVD Description

The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.