Incorrect authorization in IdentityIQ - CVE-2026-4857
Published: April 17, 2026
IdentityIQ
SailPoint
Description
The vulnerability allows a remote user to create new IdentityIQ objects.
The vulnerability exists due to improper authorization in the Debug UI when handling access to debug pages. A remote privileged user can use the Debug Pages Read Only capability or a custom capability with the ViewAccessDebugPage SPRight to create new IdentityIQ objects.
User interaction is required.