CVE-2024-39669: Soffid Iam

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.

Affected products

  • Soffid Iam: before 3.5.39 (fixed in 3.5.39)

Published 2024-06-27. Last modified 2026-06-17.