What is CVE-2026-18360?
CVE-2026-18360 is a stored cross-site scripting (XSS) vulnerability found in the 'custom attributes' function of the IRIS web application, affecting version 2.4.26 and possibly others. This allows an attacker to hijack user sessions or inject malicious scripts. It is recommended to update the application to the latest version.
Azərbaycanca: CVE-2026-18360, IRIS veb tətbiqinin 2.4.26 və ola bilsin ki, digər versiyalarında 'custom attributes' funksiyası vasitəsilə saxlanılan (stored) cross-site scripting (XSS) zəifliyidir. Bu zəiflik təcavüzkara istifadəçi sessiyasını ələ keçirməyə və ya zərərli skript quraşdırmağa imkan verir. Tətbiqi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which version of IRIS is confirmed to be affected by CVE-2026-18360?
CVE-2026-18360 is confirmed to affect version 2.4.26 of the IRIS web application, and possibly other versions as well.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.