A vulnerability, which was classified as problematic, was found in SBA Research iris-web 2.4.26. This impacts an unknown function. Executing a manipulation can lead to improper restriction of excessive authentication attempts.

This vulnerability appears as CVE-2026-16971. The attack may be performed from remote. There is no available exploit.