CVE-2026-12341
EUVD-2026-4606420.07.2026, 19:17
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sailpoint | identityiq | 𝑥 < 8.3 |
| sailpoint | identityiq | 8.3 |
| sailpoint | identityiq | 8.3:patch1 |
| sailpoint | identityiq | 8.3:patch2 |
| sailpoint | identityiq | 8.3:patch3 |
| sailpoint | identityiq | 8.3:patch4 |
| sailpoint | identityiq | 8.3:patch5 |
| sailpoint | identityiq | 8.4 |
| sailpoint | identityiq | 8.4:patch1 |
| sailpoint | identityiq | 8.4:patch2 |
| sailpoint | identityiq | 8.4:patch3 |
| sailpoint | identityiq | 8.4:patch4 |
| sailpoint | identityiq | 8.5 |
| sailpoint | identityiq | 8.5:patch1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration