CVE-2026-12342
9.6 CRITICALPublished 2026-09-28 · Updated 2026-09-29
AI risk analysis
- Summary
- This flaw allows unauthenticated users to execute arbitrary code on the IdentityIQ server due to improper input validation, posing a critical risk.
- Exploitability
- Exploitation is relatively straightforward as it requires no authentication, making it accessible to any attacker.
- Blast radius
- If exploited, this could lead to complete server compromise and potential data exfiltration or destruction.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest version of IdentityIQ immediately.
rcewebunauthcritical
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-20
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-95675
- CRITICALCVE-2026-88771
- CRITICALCVE-2023-54399
- CRITICALCVE-2026-102304
- CRITICALCVE-2026-102316
- CRITICALCVE-2026-102331
- CRITICALCVE-2026-13249
- HIGHCVE-2026-18895PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.