What is CVE-2026-18361?
CVE-2026-18361 is a Stored Cross-Site Scripting (XSS) vulnerability found in the datastore upload function of the IRIS web application version 2.4.26 and possibly others. It allows an attacker to execute malicious scripts in a user's browser. Administrators should immediately apply the security patch or temporarily disable the affected function.
Azərbaycanca: CVE-2026-18361, IRIS veb tətbiqinin 2.4.26 versiyasında (və ehtimal ki, digər versiyalarında) datastore yükləmə funksiyasında aşkar edilmiş Stored Cross-Site Scripting (XSS) zəifliyidir. Bu, təcavüzkara istifadəçi brauzerində zərərli skript işlətməyə imkan verir. Tətbiq sahibləri dərhal təhlükəsizlik yeniləməsini tətbiq etməli və ya müvəqqəti olaraq zəif funksiyanı sıradan çıxarmalıdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which application does CVE-2026-18361 affect?
This vulnerability affects the IRIS web application version 2.4.26 and possibly other versions.
What should administrators do after CVE-2026-18361 is discovered?
Administrators should immediately apply the security patch or temporarily disable the vulnerable datastore upload function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.