← Back to search

CVE-2026-12342

9.6 CRITICAL

Published 2026-09-28 · Updated 2026-09-29

AI risk analysis

Summary
This flaw allows unauthenticated users to execute arbitrary code on the IdentityIQ server due to improper input validation, posing a critical risk.
Exploitability
Exploitation is relatively straightforward as it requires no authentication, making it accessible to any attacker.
Blast radius
If exploited, this could lead to complete server compromise and potential data exfiltration or destruction.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of IdentityIQ immediately.
rcewebunauthcritical

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-20

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.