CVE-2026-12341
Sailpoint · Published July 20, 2026
9.8
CVSS v3.1
CRITICALPatch availableGet patch
Description
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
Affected Products
- Identityiq < 8.3
- Identityiq
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H