Skip to content
CVE-2026-12342

CVE-2026-12342

Mondoo • September 29, 2026

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

Vulnerability: CVE-2026-12342 is a remote code execution vulnerability affecting all versions of SailPoint IdentityIQ that allows unauthenticated users to execute arbitrary code on the IdentityIQ server due to improper input validation of web service API content.

Trending: The vulnerability is gaining attention on social media platforms like Bluesky, with security researchers highlighting that the flaw enables attackers to control IdentityIQ servers through unverified data sent to its web interface, making it a critical concern for organizations using the affected identity management platform.

CVE-2026-12342 - identityiq All versions of SailPoint IdentityIQ can be fooled into executing code because it does not properly verify data sent to its web interface. This means someone could control… Too many irrelevant or confusing CVEs? Use stackflag.com #identityiq #sailpoint #CVE #infosec

Extracted Entities