CVE-2026-4857HIGH 8.4EPSS p18.3%

CVE-2026-4857CVE-2026-4857

Description

IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new IdentityIQ objects.  Until a remediating security fix or patches containing this security fix are installed, the Debug Pages Read Only capability and any custom capabilities that contain the ViewAccessDebugPage SPRight should be unassigned from all identities and workgroups.

Scoring

CVSS 3.18.4 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
EPSS0.27% probability of exploitation · percentile 18.3% · 2026-06-19T12:03:05Z
Published2026-04-15
Last modified2026-04-17

Underlying weaknesses· 1

CWE-863

References

  1. https://www.sailpoint.com/security-advisories/sailpoint-identityiq-debug-ui-incorrect-authorization-vulnerability-cve-2026-4857

1

TypeTargetConfidenceTier
WeaknessIncorrect Authorizationcwe-8630%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-5712
CVE
CVE-2025-49851
CVE
CVE-2026-24305
CVE
CVE-2026-5786
CVE
CVE-2025-40897
CVE
CVE-2025-49853
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.