CVE-2026-12341
HIGH
8.8
CVSS 3.1
Description
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
Metadata
Severity & Metrics
8.8
HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| SailPoint Technologies | IdentityIQ | — | 8.5 ≤ 8.5p1, 8.4 ≤ 8.4p4, 8.3 ≤ 8.3p5 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-287 | cna | CWE-287 |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 8.8 | HIGH | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
References (1)