CyberICT

CVE-2026-12341

Sailpoint · Published July 20, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.

Affected Products

  • Identityiq < 8.3
  • Identityiq

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H