A vulnerability was found in sba-research IRIS 2.4.26 and classified as problematic. Affected by this vulnerability is the function assets. The manipulation results in cross site scripting.

This vulnerability is known as CVE-2026-16969. It is possible to launch the attack remotely. No exploit is available.