What is CVE-2026-16971?
The IRIS web application in version 2.4.26 lacks protection against brute-force attacks on its MFA validation. This could allow attackers to bypass multi-factor authentication through repeated attempts. Administrators should immediately implement rate-limiting or account lockout policies for the MFA process.
Azərbaycanca: IRIS veb tətbiqinin 2.4.26 versiyasında MFA doğrulama mexanizmi brute-force hücumlarına qarşı qorunmur. Bu, təcavüzkarlara çoxfaktorlu autentifikasiyanı keçməyə imkan verə bilər. Tətbiq sahibləri dərhal MFA prosesinə rate-limiting və ya hesab kilidləmə tədbirləri əlavə etməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which version of the IRIS web application is affected by the MFA brute-force vulnerability?
Version 2.4.26 of the IRIS web application is affected by this vulnerability.
What measures should administrators take to mitigate this MFA vulnerability?
Administrators should implement rate-limiting or account lockout policies for the MFA process.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.