This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 28 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
Title SailPoint IdentityIQ Improper Form Validation Vulnerability
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SailPoint

Published:

Updated: 2026-09-28T15:45:21.242Z

Reserved: 2026-06-15T16:30:51.596Z

Link: CVE-2026-12342

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:13.460

Modified: 2026-09-28T16:17:13.460

Link: CVE-2026-12342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:30:04Z

Weaknesses