Threat intelligence dashboard
CVE-2026-12342critical

SailPoint IdentityIQ Improper Form Validation Vulnerability

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

Risk score

9.6

CVSS 3.1

Vendor
SailPoint Technologies
Product
IdentityIQ
CWE
CWE-20
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

IdentityIQ

SailPoint Technologies

Version / rangeStatusType
8.5 to 8.5p2affectedcustom
8.4 to 8.4p4affectedcustom
8.3 to 8.3p5affectedcustom

Technical metrics

9.6

CVSS 3.1

Severity
critical
Source
SailPoint
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H