A vulnerability was found in SBA Research IRIS 2.4.26. It has been declared as problematic. This affects an unknown part of the component Datastore. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-18361. The attack can be launched remotely. No exploit exists.