CVE-2026-4857: SailPoint IdentityIQ Debug UI Incorrect Authorization
IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new IdentityIQ objects. Until a remediating security fix or patches containing this security fix are installed, the Debug Pages Read Only capability and any custom capabilities that contain the ViewAccessDebugPage SPRight should be unassigned from all identities and workgroups.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4857?
CVE-2026-4857 is categorized as a high severity vulnerability due to its potential to expose sensitive information through incorrect authorization.
How do I fix CVE-2026-4857?
To fix CVE-2026-4857, upgrade to IdentityIQ version 8.5p2 or 8.4p4 or later.
What systems are affected by CVE-2026-4857?
CVE-2026-4857 affects SailPoint IdentityIQ versions 8.5 and 8.4 prior to specific patch levels.
What causes the vulnerability in CVE-2026-4857?
CVE-2026-4857 is caused by incorrect authorization handling in the Debug UI, allowing unauthorized access to sensitive data.
Who is at risk due to CVE-2026-4857?
Authenticated users with certain permissions in SailPoint IdentityIQ are at risk of being able to access debug information improperly.