
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12341 is an improper authentication vulnerability in SailPoint IdentityIQ that allows unauthenticated attackers to gain unauthorized access to protected APIs and sensitive data due to improper validation of OAuth bearer tokens. The vulnerability affects all versions of IdentityIQ, with specific confirmed affected versions including 8.3 through 8.3p5, 8.4 through 8.4p4, and 8.5 through 8.5p1, as well as all versions prior to 8.3. It was published on July 20, 2026, with a patch made available by SailPoint on the same date. The NVD assigns a CVSS v3.1 base score of 9.8 (Critical), while the GitHub Advisory Database scores it 8.8 (High) (GitHub Advisory, SailPoint).
The root cause is classified as CWE-287 (Improper Authentication): IdentityIQ fails to properly validate OAuth bearer tokens presented to its protected API endpoints, allowing an attacker to bypass authentication controls entirely. An unauthenticated remote attacker can craft or present invalid/forged OAuth bearer tokens that the application incorrectly accepts as legitimate, granting access to protected REST APIs and underlying data. No privileges are required to initiate the attack, and the attack vector is network-accessible, making this exploitable from any internet-facing IdentityIQ deployment. No public proof-of-concept code has been identified at this time (GitHub Advisory, SailPoint).
Successful exploitation allows an unauthenticated attacker to access protected APIs and sensitive data managed by IdentityIQ, which as an identity governance platform may include user credentials, access entitlements, role assignments, and audit logs across connected enterprise systems. The CVSS assessment indicates high impact to confidentiality, integrity, and availability, meaning an attacker could read, modify, or disrupt identity data. Given IdentityIQ's role as a central identity and access management hub, compromise could facilitate lateral movement across connected enterprise applications and directories (GitHub Advisory, SailPoint).
As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment notes the vulnerability is not currently being exploited and is not fully automatable. The EPSS score is approximately 0.216%, placing it in the 12th percentile for exploitation likelihood within 30 days. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the disclosure date. Despite the low current exploitation evidence, the zero-privilege, network-accessible attack vector represents significant risk for exposed deployments.
/identityiq/rest/)./identityiq/rest/identities, /identityiq/rest/roles).Authorization: Bearer <token> header./identityiq/rest/) from unauthenticated or unknown source IPs; high volume of API requests without corresponding user session activity.SailPoint has released a patch addressing this vulnerability; organizations should apply the security update available via the SailPoint security advisories page immediately (SailPoint). As interim mitigations, restrict network access to IdentityIQ API endpoints using firewall rules or network segmentation to limit exposure to trusted networks only. Organizations should also review OAuth token validation configurations, monitor API access logs for anomalous activity, and consider implementing additional authentication controls such as multi-factor authentication for API access where supported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."