CVE-2026-12342: SailPoint IdentityIQ Improper Form Validation Vulnerability
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An unauthenticated attacker can exploit it remotely against an affected IdentityIQ server. No user interaction or existing account is required.
Which deployments are affected?
The vulnerability impacts all versions of SailPoint IdentityIQ. The provided information does not identify a configuration requirement or a version that is unaffected.
What is the potential impact of successful exploitation?
Successful exploitation can result in remote code execution on the IdentityIQ server. The supplied severity vector indicates high impact to confidentiality, integrity, and availability, with scope changed.
What attack surface is involved?
The issue is in validation of submitted web service API content. Systems where the IdentityIQ web service API is reachable by an attacker are the relevant exposure point.