CVE-2026-12342

EUVD-2026-88337
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
SailPointCNA
9.6 CRITICAL
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
sailpointidentityiq
8.5 ≤
𝑥
≤ 8.5p2
CNA
sailpointidentityiq
8.4 ≤
𝑥
≤ 8.4p4
CNA
sailpointidentityiq
8.3 ≤
𝑥
≤ 8.3p5
CNA