A vulnerability was found in dfir-iris iris-web 2.4.26. It has been classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes cross site scripting.

This vulnerability is handled as CVE-2026-18360. The attack can be initiated remotely. There is not any exploit available.