CVE-2026-12341
published 2026-07-20CVE-2026-12341: This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper…
PriorityP356high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.22%
12.2th percentile
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sailpoint_technologies | identityiq | 8.3 – 8.3p5 | — |
| sailpoint_technologies | identityiq | 8.4 – 8.4p4 | — |
| sailpoint_technologies | identityiq | 8.5 – 8.5p1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SailPoint IdentityIQ up to 8.3p5/8.4p4/8.5p1 OAuth Bearer Token improper authorization
vuldb·2026-07-20·CVSS 8.8
CVE-2026-12341 [HIGH] SailPoint IdentityIQ up to 8.3p5/8.4p4/8.5p1 OAuth Bearer Token improper authorization
A vulnerability has been found in SailPoint IdentityIQ up to 8.3p5/8.4p4/8.5p1 and classified as critical. This impacts an unknown function of the component OAuth Bearer Token. This manipulation causes improper authorization.
The identification of this vulnerability is CVE-2026-12341. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
ghsa_unreviewed·2026-07-20
CVE-2026-12341 [HIGH] CWE-287 This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-20
Published