---
id: CVE-2026-12342
title: |-
  This vulnerability
  impacts all versions of IdentityIQ and allows an unauthenticated user remote
  code execution on the IdentityIQ server due to improper input validation of
  submitted web service API content.
summary: |-
  This vulnerability
  impacts all versions of IdentityIQ and allows an unauthenticated user remote
  code execution on the IdentityIQ server due to improper input validation of
  submitted web service API content.
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: SailPoint Technologies
product: IdentityIQ
affected:
  - IdentityIQ >= 8.5 <= 8.5p2
  - IdentityIQ >= 8.4 <= 8.4p4
  - IdentityIQ >= 8.3 <= 8.3p5
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T16:17:13.460'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12342'
references:
  - url: 'https://www.sailpoint.com/security-advisories/'
    label: psirt@sailpoint.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T16:15:01.369Z'
---

## Overview

This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
