High severity8.8NVD Advisory· Published Jul 20, 2026· Updated Jul 30, 2026
CVE-2026-12341
CVE-2026-12341
Description
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
Affected products
15cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:*range: <8.3
- cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.3:patch2:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.3:patch3:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.3:patch4:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.3:patch5:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.4:-:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.4:patch1:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.4:patch2:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.4:patch3:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.4:patch4:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.5:-:*:*:*:*:*:*
- cpe:2.3:a:sailpoint:identityiq:8.5:patch1:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
1- www.sailpoint.com/security-advisories/nvdVendor Advisory
News mentions
0No linked articles in our index yet.