CVE-2026-4857
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/04/2026
Last modified:
15/04/2026
Description
IdentityIQ 8.5, all<br />
IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ<br />
8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug<br />
Pages Read Only capability or any custom capability with the ViewAccessDebugPage<br />
SPRight to incorrectly create new IdentityIQ objects. Until a remediating security fix or patches<br />
containing this security fix are installed, the Debug Pages Read Only<br />
capability and any custom capabilities that contain the ViewAccessDebugPage<br />
SPRight should be unassigned from all identities and workgroups.
Impact
Base Score 3.x
8.40
Severity 3.x
HIGH



