PT-2026-33131 · Sailpoint Technologies · Identityiq
Wildwildwes
·
Published
2026-04-15
·
Updated
2026-04-15
·
CVE-2026-4857
CVSS v3.1
8.4
High
| AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
IdentityIQ 8.5, all
IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ
8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug
Pages Read Only capability or any custom capability with the ViewAccessDebugPage
SPRight to incorrectly create new IdentityIQ objects. Until a remediating security fix or patches
containing this security fix are installed, the Debug Pages Read Only
capability and any custom capabilities that contain the ViewAccessDebugPage
SPRight should be unassigned from all identities and workgroups.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Identityiq