SailPointCVE-2026-12342
SailPoint IdentityIQ: remote code execution
Critical9.6CVE-2026-12342 · Published Sep 28, 2026 · updated Sep 30, 2026
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| IdentityIQ Product | >= 8.5, <= 8.5p2 | No fix yet |
| >= 8.4, <= 8.4p4 | No fix yet | |
| >= 8.3, <= 8.3p5 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-20
More SailPoint advisories
All SailPoint| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 20 | SailPoint IdentityIQ: improper authentication | High8.8 | No fix yet |