Description

IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new IdentityIQ objects.  Until a remediating security fix or patches containing this security fix are installed, the Debug Pages Read Only capability and any custom capabilities that contain the ViewAccessDebugPage SPRight should be unassigned from all identities and workgroups.

INFO

Published Date :

2026-04-15T18:08:45.737Z

Last Modified :

2026-04-16T03:55:39.481Z

Source :

SailPoint
AFFECTED PRODUCTS

The following products are affected by CVE-2026-4857 vulnerability.

Vendors Products
Sailpoint Technologies
  • Identityiq
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-4857.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact