EUVD Vulnerability Catalog
EUVD-2026-88337
Severity: CRITICAL
Base Score: 9.6
CVSS Version: 3.1
Vulnerability Description
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
▪
Attack Vector (AV): Adjacent Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Changed
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
SailPoint Technologies
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
SailPoint
EPSS Probability
0
Known Aliases
CVE-2026-12342
Published On
2026-09-28
Last Updated
2026-09-28