SailPoint IdentityIQ Debug UI Incorrect Authorization Vulnerability - CVE-2026-4857

Description

IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new IdentityIQ objects. Until a remediating security fix or patches containing this security fix are installed, the Debug Pages Read Only capability and any custom capabilities that contain the ViewAccessDebugPage SPRight should be unassigned from all identities and workgroups.

Affected product and versions

  • IdentityIQ 8.5 and all 8.5 patch levels prior to 8.5p2
  • IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4
  • All previous versions are not affected

Resolution

SailPoint has released IIQTC-776 for each impacted and supported version of IdentityIQ. Future patch levels will include the fixes once they become available.

CVE details

CVE ID: CVE-2026-4857
Published Date: 04/15/2026
Vulnerability Type: IdentityIQ Debug UI Incorrect Authorization Vulnerability
CWE: CWE-863
CVSS v3 Score: 8.4
CVSS v3 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H