SailPoint IdentityIQ unauthenticated RCE via web service API
Improper input validation in IdentityIQ's web service API lets an unauthenticated attacker execute arbitrary code on the server. All versions are affected.
- Vendor
- SailPoint
- Product
- IdentityIQ
- CVSS
- 9.6
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
SailPoint disclosed CVE-2026-12342 in its IdentityIQ identity governance platform. The vulnerability is rooted in insufficient validation of data submitted to the product’s web service API, allowing a remote unauthenticated attacker to execute arbitrary code on the server.
All versions of IdentityIQ are affected. SailPoint has released a patch, documented in the vendor security advisory linked above. Organizations should apply the patch as directed and review network exposure of the IdentityIQ web service API in the interim.
No active exploitation has been confirmed at time of publication.
