SECURITYCRITICALCVE-2026-12342

CVE-2026-12342: SailPoint IdentityIQ Unauthenticated Remote Code Execution

A critical, unauthenticated RCE in SailPoint IdentityIQ's web service API lets attackers execute code with no credentials.

Dylan H.

Security Team

September 29, 2026
3 min read
CVE-2026-12342: SailPoint IdentityIQ Unauthenticated Remote Code Execution

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • SailPoint IdentityIQ 8.5 — 8.5 through 8.5p2
  • SailPoint IdentityIQ 8.4 — 8.4 through 8.4p4
  • SailPoint IdentityIQ 8.3 — 8.3 through 8.3p5
  • SailPoint IdentityIQ — all prior versions

Overview

SailPoint IdentityIQ, a widely-deployed enterprise identity governance and administration (IGA) platform, is affected by a critical unauthenticated remote code execution vulnerability tracked as CVE-2026-12342. The flaw stems from improper input validation of content submitted to IdentityIQ's web service API, allowing an unauthenticated attacker to execute arbitrary code on the IdentityIQ server. The vulnerability affects all versions of the product and has been assigned a CVSS score of 9.6 (critical).


Technical Details

FieldValue
CVE IDCVE-2026-12342
SeverityCritical
CVSS Score9.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Attack VectorAdjacent Network
AuthenticationNone Required
Privileges RequiredNone
CWECWE-20 (Improper Input Validation)
Affected VersionsAll versions, including 8.5 ≤ 8.5p2, 8.4 ≤ 8.4p4, 8.3 ≤ 8.3p5

The vulnerability arises because IdentityIQ's web service API does not properly validate submitted form content before processing it, giving an attacker a path to remote code execution without ever authenticating to the platform. Note the CVSS vector's Adjacent Network attack-vector component — exploitation requires the attacker to reach the vulnerable API from the same broadcast domain or a routed segment with equivalent access, not the open internet directly, though this is a low bar in most enterprise network layouts where IdentityIQ sits reachable from a broad internal segment.


Why This Matters

  • Identity governance platforms are high-value targets. IdentityIQ sits at the center of enterprise access provisioning and deprovisioning — compromising it can let an attacker grant themselves (or anyone) access to virtually any downstream system it governs.
  • No authentication barrier. An attacker needs no valid credentials, no session, and no user interaction to trigger the flaw — only network reachability to the vulnerable web service API.
  • Full impact across the CIA triad. The CVSS vector rates confidentiality, integrity, and availability impact all as High, consistent with arbitrary code execution on the server.
  • Blast radius extends beyond IdentityIQ itself. Because IGA platforms typically hold connectors and credentials into HR systems, directories, and downstream applications, a compromised IdentityIQ server can become a pivot point into the broader identity fabric of an organization.
  • All versions are affected, meaning any IdentityIQ deployment that hasn't applied the vendor's fix is exposed regardless of how recently it was upgraded.

Remediation

  1. Apply SailPoint's security update immediately. SailPoint has published security update IIQSR-983 for each supported IdentityIQ version, available through the SailPoint Support Portal. This is the primary fix and should be prioritized above all other mitigations.
  2. Restrict network exposure of the web service API. Until the patch is applied, limit access to IdentityIQ's web service endpoints to trusted management segments only, and ensure the platform is not reachable from untrusted or overly broad internal network zones.
  3. Audit IdentityIQ access and provisioning logs for unusual API calls, unexpected process execution, or anomalous account/entitlement changes around the disclosure window.
  4. Rotate credentials and connector secrets held by IdentityIQ if there is any indication the server was exposed to untrusted network segments prior to patching.
  5. Monitor SailPoint's advisory and threat intelligence feeds for indicators of active exploitation, since unauthenticated RCE vulnerabilities in enterprise IGA platforms are prime targets once technical details circulate.

Given the unauthenticated attack path and the central role IdentityIQ plays in enterprise access control, this vulnerability should be treated as an urgent patching priority even in the absence of confirmed in-the-wild exploitation.

Sources