Sceawere

Vulnerability Detail

CVE-2026-12342UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IdentityIQ Unauthenticated Remote Code Execution

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
4h ago
Vendor
SailPoint Technologies
Product
IdentityIQ
Attack Type
CWE-20 Improper input validation
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-09-28T16:17:13.460Z",
  "pubdate": "2026-09-28T16:17:13.460Z",
  "executiveSummary": "This vulnerability is a critical Remote Code Execution (RCE) flaw residing within all versions of IdentityIQ. The vulnerability stems from improper input validation performed on web service API requests.\nAs an unauthenticated vulnerability, it allows remote, unprivileged actors to achieve arbitrary code execution on the underlying IdentityIQ server. Successful exploitation grants the attacker full control over the application environment, potentially leading to total system compromise, data exfiltration, or lateral movement within the network.\nThe risk profile is classified as critical due to the lack of required authentication and the severity of the impact. Attackers do not need valid credentials to initiate the exploit, making the system highly susceptible to automated or manual exploitation attempts directed at the public-facing API endpoints.",
  "technicalDetails": "The root cause of this vulnerability is insufficient input sanitization and validation logic within the IdentityIQ web service API layer. When the application processes incoming API requests, it fails to properly inspect and filter malicious payloads contained within submitted content.\nThe attack flow initiates when an unauthenticated remote actor sends a specially crafted, malicious payload to an IdentityIQ web service API endpoint. Because the application processes this input without adequate validation, it inadvertently interprets or executes the embedded malicious content within the server-side runtime environment.\nIn the context of IdentityIQ, this allows for the injection and execution of arbitrary code, effectively bypassing all authentication and authorization boundaries. The vulnerable component is the web service API handler responsible for interpreting client-submitted data. Since this handler exists in all versions of IdentityIQ, the entire product suite is inherently susceptible to this RCE condition.\nExploitation does not require prior knowledge of the internal system architecture, as the attack is executed through standard network protocols used to interface with the web service. Once the malicious payload is successfully parsed, the IdentityIQ server executes the attacker's commands with the privileges assigned to the web application process. This often leads to full system control, allowing the attacker to read, modify, or delete sensitive identity data, establish persistent backdoors, or leverage the compromised server as a pivot point to attack other internal network resources.\nThe vulnerability is primarily network-exposed, meaning any IdentityIQ deployment reachable via the internet—or an internal network if the attacker has access—is at immediate risk. The lack of validation logic implies that the server does not enforce any integrity checks on the incoming data stream, allowing for the delivery of complex payloads such as serialized objects, scripts, or direct system calls, depending on the specific API implementation and language runtime nuances."
}
CVE-2026-12342: IdentityIQ Unauthenticated Remote Code Execution (CRITICAL Severity, CVSS: 9.6) | Sceawere