Skip to content
feed: live
>_0dayNews
threat intel

SailPoint Patches Critical Unauth RCE in IdentityIQ

SailPoint patches CVE-2026-12342, a CVSS 9.6 unauthenticated RCE in IdentityIQ. All versions are affected. Apply the vendor patch immediately.

SailPoint Patches Critical Unauth RCE in IdentityIQ
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
kilobaudDave "Kilobaud" Ferris·Published ·1 min read

SailPoint has published a security advisory for CVE-2026-12342 (CVSS 9.6, Critical), a remote code execution vulnerability that affects every version of its IdentityIQ platform. An unauthenticated attacker with access to the product’s web service API can execute arbitrary code on the server. No credentials are required.

IdentityIQ is SailPoint’s on-premises identity governance platform, deployed widely across enterprises for access provisioning, lifecycle management, and compliance workflows. An unauthenticated RCE in an identity governance system carries specific weight: the same platform that controls access to the rest of the environment becomes the entry point.

The flaw stems from improper input validation of data submitted to IdentityIQ’s web service API, per SailPoint’s advisory. SailPoint has released a patch; the advisory page contains version-specific remediation details. There is no confirmed report of active exploitation as of this writing.

For environments where immediate patching is not possible, web service API endpoints that do not need to be accessible from untrusted networks should not be. Inventory any internet-accessible IdentityIQ instances and move them to the front of the patching queue.

Identity governance platforms have seen a steady stream of critical vulnerabilities this month. Earlier this week, Red Hat disclosed four separate flaws in Keycloak (Red Hat Patches Four Keycloak IAM Flaws), and in the same period a CVSS 9.8 unauthenticated RCE surfaced in the REDCap research data platform (REDCap Patches CVSS 9.8 Unauth RCE via Survey Route).

There is no confirmed active exploitation yet. Identity governance systems have historically become attacker targets quickly once a working RCE lands in the wild. Patch this one before that clock runs out.

Related CVEs
  • [ CRITICAL ]CVE-2026-12342SailPoint IdentityIQ unauthenticated RCE via web service API

Found this useful? Share it.