CVE-2026-12341

EUVD-2026-46064
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11.96%
Affected Products (NVD)
VendorProductVersion
sailpointidentityiq
𝑥
< 8.3
sailpointidentityiq
8.3
sailpointidentityiq
8.3:patch1
sailpointidentityiq
8.3:patch2
sailpointidentityiq
8.3:patch3
sailpointidentityiq
8.3:patch4
sailpointidentityiq
8.3:patch5
sailpointidentityiq
8.4
sailpointidentityiq
8.4:patch1
sailpointidentityiq
8.4:patch2
sailpointidentityiq
8.4:patch3
sailpointidentityiq
8.4:patch4
sailpointidentityiq
8.5
sailpointidentityiq
8.5:patch1
𝑥
= Vulnerable software versions