This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.

Project Subscriptions

Vendors Products
Sailpoint Technologies Subscribe
Identityiq Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 28 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Sailpoint Technologies
Sailpoint Technologies identityiq
Vendors & Products Sailpoint Technologies
Sailpoint Technologies identityiq

Mon, 28 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
Title SailPoint IdentityIQ Improper Form Validation Vulnerability
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SailPoint

Published:

Updated: 2026-09-28T18:02:57.009Z

Reserved: 2026-06-15T16:30:51.596Z

Link: CVE-2026-12342

cve-icon Vulnrichment

Updated: 2026-09-28T17:53:16.146Z

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:13.460

Modified: 2026-09-28T18:17:21.410

Link: CVE-2026-12342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:45:04Z

Weaknesses