Skip to content
Critical Remote Code Execution Vulnerability in SailPoint IdentityIQ

Critical Remote Code Execution Vulnerability in SailPoint IdentityIQ

First seen 29 Sep 2026, 19:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 20:19 UTC
  • •CVE-2026-12342 allows remote code execution on SailPoint IdentityIQ servers.
  • •All versions of IdentityIQ are affected, posing a significant risk to organizations.
  • •Immediate action is recommended due to the critical nature of the vulnerability.

A newly discovered vulnerability, CVE-2026-12342, affects all versions of SailPoint IdentityIQ, allowing unauthenticated users to execute arbitrary code on the server due to improper input validation of web service API content. This flaw has gained significant attention on social media, with security researchers warning that attackers can control IdentityIQ servers through unverified data sent to its web interface. The vulnerability was published on September 28, 2026, and is considered a critical concern for organizations utilizing this identity management platform. Other vulnerabilities affecting SailPoint IdentityIQ have been reported, including CVE-2026-12341, CVE-2026-5712, and CVE-2026-4857, highlighting ongoing security issues within the platform. Organizations are urged to assess their exposure and implement necessary security measures promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-01-31
CVE-2022-45435 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
CVE-2026-12342 published
A remote code execution vulnerability in SailPoint IdentityIQ was disclosed, impacting all versions.
Mondoo
2026-09-29
SailPoint security advisories updated
Multiple vulnerabilities, including CVE-2026-12341 and CVE-2026-5712, were reported affecting SailPoint IdentityIQ.
SailPoint

More articles in this cluster (3)

Following this threat?

Track CVE-2022-45435 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed