CVE-2026-4857
8.4SailPoint Technologies · IdentityIQ
SailPoint IdentityIQ allows authenticated users with specific debug permissions to incorrectly create unauthorized objects within the system.
Executive summary
A high-severity authorization vulnerability in SailPoint IdentityIQ allows authenticated users with elevated debug capabilities to perform unauthorized object creation, posing a significant risk to system integrity.
Vulnerability
The vulnerability is an incorrect authorization flaw (CWE-863) that allows authenticated users assigned the Debug Pages Read Only capability, or custom capabilities including the ViewAccessDebugPage SPRight, to incorrectly create new IdentityIQ objects.
Business impact
The ability for unauthorized users to create objects within an identity governance platform can lead to privilege escalation, unauthorized access to sensitive data, or the creation of backdoors for persistent access. Given the CVSS score of 8.4, this vulnerability represents a high risk to organizational security posture, as it undermines the core access control mechanisms of the identity management suite.
Remediation
Immediate Action: Upgrade to IdentityIQ 8.5p2 or 8.4p4 or later as provided by the vendor. Until these patches are applied, administrators should unassign the Debug Pages Read Only capability and any custom capabilities containing the ViewAccessDebugPage SPRight from all identities and workgroups.
Proactive Monitoring: Review audit logs for suspicious object creation events or unusual modifications originating from accounts that possess debug or administrative capabilities.
Compensating Controls: Implement strict Role Based Access Control (RBAC) reviews to ensure that debug permissions are restricted to the absolute minimum number of authorized personnel required for system maintenance.
Exploitation status
Public Exploit Available: No — no confirmed public exploit exists.
Analyst recommendation
Due to the high CVSS score and the sensitive nature of the impacted software, immediate remediation is required. Security teams should prioritize identifying all identities currently assigned the vulnerable debug capabilities and revoke these permissions until the vendor-supplied patches are successfully deployed.
More SailPoint Technologies CVEs
Sources
Originally found and disclosed by wildwildwes, per the CVE Program record.