CVE-2026-12341
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SailPoint Technologies | IdentityIQ | 8.5 <= 8.5p1 | affected |
| SailPoint Technologies | IdentityIQ | 8.4 <= 8.4p4 | affected |
| SailPoint Technologies | IdentityIQ | 8.3 <= 8.3p5 | affected |
Weaknesses
- CWE-287: CWE-287
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.