CVE-2026-12341
—CVSS 3.1
9.8 critical
EPSS
<1%p12
Published
()
Modified
Description
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
- Vendors
- sailpoint
- Products
- identityiq
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.