Security · October 2, 2026
SailPoint IdentityIQ Exposes Critical Vulnerability
A serious vulnerability has been revealed in SailPoint's identity management product, SailPoint IdentityIQ. A patch is being provided for affected versions.
On September 28, 2026, the company published a security advisory detailing the input validation vulnerability identified as CVE-2026-12342. The vulnerability arises from inadequate validation of content sent to the web service API, allowing unauthorized input to be processed. This means that code execution on the IdentityIQ server can occur without authentication from adjacent networks.
The Common Vulnerability Scoring System (CVSSv3.1) has assigned a base score of 9.6 to this vulnerability, categorizing its severity as Critical, the highest tier.
The company is offering fixes for affected versions and plans to include these corrections in upcoming patch releases.