Remote Code Execution Vulnerability in IdentityIQ by SailPoint
CVE-2026-12342
9.6CRITICAL
What is CVE-2026-12342?
This vulnerability in IdentityIQ affects all versions by allowing an unauthenticated user to execute arbitrary code remotely. The flaw stems from inadequate input validation of content submitted through the web service API, potentially compromising the security of the IdentityIQ server. Organizations using IdentityIQ should take immediate action to review their systems and apply necessary security patches to mitigate this risk.
Affected Version(s)
IdentityIQ 8.5 <= 8.5p2
IdentityIQ 8.5 <= 8.5p2
IdentityIQ 8.4 <= 8.4p4
