Remote Code Execution Vulnerability in IdentityIQ by SailPoint
CVE-2026-12342

9.6CRITICAL

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-12342?

This vulnerability in IdentityIQ affects all versions by allowing an unauthenticated user to execute arbitrary code remotely. The flaw stems from inadequate input validation of content submitted through the web service API, potentially compromising the security of the IdentityIQ server. Organizations using IdentityIQ should take immediate action to review their systems and apply necessary security patches to mitigate this risk.

Affected Version(s)

IdentityIQ 8.5 <= 8.5p2

IdentityIQ 8.5 <= 8.5p2

IdentityIQ 8.4 <= 8.4p4

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

taise
.