Junglewise Threat Intelligence

CVE-2026-12341: SailPoint IdentityIQ improper authentication in OAuth token validation

CVE-2026-12341 · Severity: high · CVSS 8.8 · Published 2026-07-20

Executive brief

SailPoint IdentityIQ, a platform used by organizations to manage user identities and access permissions, contains a security flaw that allows unauthorized individuals to access sensitive data. An attacker can bypass security checks to reach protected application interfaces without needing a username or password. This could lead to the exposure of confidential corporate identity data or unauthorized changes to user access rights.

Technical details

A vulnerability in SailPoint IdentityIQ stems from improper authentication (CWE-287) due to the incorrect validation of OAuth bearer tokens. An unauthenticated remote attacker can exploit this flaw to gain unauthorized access to protected APIs and sensitive data. The attack vector is network-based and requires no prior privileges, though the CVSS vector suggests some level of user interaction may be involved. All versions of IdentityIQ are reported as affected, including the 8.3, 8.4, and 8.5 release branches.

Affected products

  • SailPoint Technologies IdentityIQ All versions (including 8.3p5, 8.4p4, 8.5p1 and earlier)

Timeline

  • 2026-07-20: disclosed
  • 2026-07-20: advisory

References