CVE-2026-12342 PUBLISHED

SailPoint IdentityIQ Improper Form Validation Vulnerability

Assigner: SailPoint
Reserved: 15.06.2026 Published: 28.09.2026 Updated: 29.09.2026

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor SailPoint Technologies
Product IdentityIQ
Versions Default: affected
  • affected from 8.5 to 8.5p2 (incl.)
  • affected from 8.4 to 8.4p4 (incl.)
  • affected from 8.3 to 8.3p5 (incl.)

Credits

  • taise reporter

References

Problem Types

  • CWE-20 Improper input validation CWE

Impacts

  • CAPEC-76 Manipulating Web Input to File System Calls