SailPoint IdentityIQ Improper Form Validation Vulnerability – CVE-2026-12342
Description
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
Affected product and versions
- IdentityIQ 8.5 and all 8.5 patch levels through 8.5p2
- IdentityIQ 8.4 and all 8.4 patch levels through 8.4p4
- IdentityIQ 8.3 and all 8.3 patch levels through 8.3p5
- All previous versions are affected
Resolution
SailPoint has released IIQSR-983 for each impacted and supported version of IdentityIQ. Future patch levels will include the fixes once they become available.
CVE details
CVE ID: CVE-2026-12342
Published Date: 09/28/2026
Vulnerability Type: IdentityIQ Improper Form Validation Vulnerability
CWE: CWE-20
CVSS v3 Score: 9.6
CVSS v3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H