Set Sail: Remote Code Execution in SailPoint IQService via Default Encryption Key
netspi.com | vulnerability | #rce | #encryption | #default-credentials | #iam | #sailpoint | #iqservice | #network-pentesting
Summary
SailPoint IQService before the May 2025 update allows RCE with default settings: the RPC server uses a hard-coded key without authentication or TLS, letting attackers execute arbitrary code.
- Published
- Collected
Skip to content