VYPR
High severity8.8NVD Advisory· Published Jul 20, 2026· Updated Jul 30, 2026

CVE-2026-12341

CVE-2026-12341

Description

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.

Affected products

15
  • cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:sailpoint:identityiq:*:*:*:*:*:*:*:*range: <8.3
    • cpe:2.3:a:sailpoint:identityiq:8.3:-:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.3:patch1:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.3:patch2:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.3:patch3:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.3:patch4:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.3:patch5:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.4:-:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.4:patch1:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.4:patch2:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.4:patch3:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.4:patch4:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.5:-:*:*:*:*:*:*
    • cpe:2.3:a:sailpoint:identityiq:8.5:patch1:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.