Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-12342: SailPoint IdentityIQ enables remote code execution by anyone

CVE-2026-12342 · published 12 days ago
Summary

All versions of SailPoint IdentityIQ can be fooled into executing code because it does not properly verify data sent to its web interface. This means someone could control the IdentityIQ server without logging in and could see or change employee identity information. Install the security fix from SailPoint immediately and restrict external access to the system until it is patched.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
sailpoint technologies identityiq <= 8.5p2
Original advisory text
SailPoint IdentityIQ Improper Form Validation Vulnerability
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-20Improper Input Validation
Timeline
Published28 Sep 2026
Updated7 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-12342 · MITRE
Track software like this
Free during beta