216.73.216.233

CVE-2026-4857

· Published 15/04/2026 19:16 · Modified 15/04/2026 19:16

Labels: CVE-2026-4857 2026-04-15CVE-2026-4857CWE-863[email protected]

Essential information

Published
15/04/2026 19:16
Modified
15/04/2026 19:16
Author
Creator
CVSS
8.4 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new IdentityIQ objects.  Until a remediating security fix or patches containing this security fix are installed, the Debug Pages Read Only capability and any custom capabilities that contain the ViewAccessDebugPage SPRight should be unassigned from all identities and workgroups.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sailpoint / identityiq cpe:2.3:a:sailpoint:identityiq:8.5:*:*:*:*:*:*:*
sailpoint / identityiq cpe:2.3:a:sailpoint:identityiq:8.4:*:*:*:*:*:*:*

References