CVE-2026-16970
MEDIUM
NVD
CVSS Score
4.2
Severity
MEDIUM
Published
Jul 30, 2026
Vendor
unknown
Description
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.