SailPointCVE-2026-12341
SailPoint IdentityIQ: improper authentication
High8.8CVE-2026-12341 · Published Jul 20, 2026 · updated Jul 30, 2026
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| IdentityIQ Product | >= 8.5, <= 8.5p1 | No fix yet |
| >= 8.4, <= 8.4p4 | No fix yet | |
| >= 8.3, <= 8.3p5 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-287