CVE-2026-12341

Summary

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.

Affected Software

VendorProductVersion RangeStatus
SailPoint TechnologiesIdentityIQ8.5 <= 8.5p1affected
SailPoint TechnologiesIdentityIQ8.4 <= 8.4p4affected
SailPoint TechnologiesIdentityIQ8.3 <= 8.3p5affected

Weaknesses

  • CWE-287: CWE-287

References