Description
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.
Published: 2026-09-28
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Sailpoint Technologies
Sailpoint Technologies identityiq
Vendors & Products Sailpoint Technologies
Sailpoint Technologies identityiq

Mon, 28 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
Title SailPoint IdentityIQ Improper Form Validation Vulnerability
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Sailpoint Technologies Identityiq
cve-icon MITRE

Status: PUBLISHED

Assigner: SailPoint

Published:

Updated: 2026-09-28T18:02:57.009Z

Reserved: 2026-06-15T16:30:51.596Z

Link: CVE-2026-12342

cve-icon Vulnrichment

Updated: 2026-09-28T17:53:16.146Z

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:13.460

Modified: 2026-09-28T18:17:21.410

Link: CVE-2026-12342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:45:04Z

Weaknesses