What is CVE-2026-16970?
The logout functionality in IRIS web application version 2.4.26 is ineffective, allowing stolen session cookies to be misused for a long time. Users should urgently update the application and implement additional security measures to prevent session hijacking.
Azərbaycanca: IRIS veb tətbiqinin 2.4.26 versiyasında çıxış funksiyası effektiv deyil, oğurlanmış session cookie-lər uzun müddət sui-istifadə edilə bilər. İstifadəçilər həssas sessiyaların ələ keçirilmə riskinə qarşı təcili olaraq tətbiqi yeniləməli və əlavə təhlükəsizlik tədbirləri görməlidir.
FAQ2
In which version of the IRIS web application is the logout functionality problematic?
This issue has been identified in version 2.4.26 of the IRIS web application.
How does this vulnerability allow stolen session cookies to be misused?
Because the logout functionality is ineffective, stolen session cookies can be misused for a long period of time.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.