CVE-2026-12341

EUVD-2026-46064
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
SailPointCNA
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
sailpointidentityiq
8.5 ≤
𝑥
≤ 8.5p1
CNA
sailpointidentityiq
8.4 ≤
𝑥
≤ 8.4p4
CNA
sailpointidentityiq
8.3 ≤
𝑥
≤ 8.3p5
CNA