CVE-2026-12341
SailPoint IdentityIQ vulnerability analysis and mitigation

Overview

CVE-2026-12341 is an improper authentication vulnerability in SailPoint IdentityIQ that allows unauthenticated attackers to gain unauthorized access to protected APIs and sensitive data due to improper validation of OAuth bearer tokens. The vulnerability affects all versions of IdentityIQ, with specific confirmed affected versions including 8.3 through 8.3p5, 8.4 through 8.4p4, and 8.5 through 8.5p1, as well as all versions prior to 8.3. It was published on July 20, 2026, with a patch made available by SailPoint on the same date. The NVD assigns a CVSS v3.1 base score of 9.8 (Critical), while the GitHub Advisory Database scores it 8.8 (High) (GitHub Advisory, SailPoint).

Technical details

The root cause is classified as CWE-287 (Improper Authentication): IdentityIQ fails to properly validate OAuth bearer tokens presented to its protected API endpoints, allowing an attacker to bypass authentication controls entirely. An unauthenticated remote attacker can craft or present invalid/forged OAuth bearer tokens that the application incorrectly accepts as legitimate, granting access to protected REST APIs and underlying data. No privileges are required to initiate the attack, and the attack vector is network-accessible, making this exploitable from any internet-facing IdentityIQ deployment. No public proof-of-concept code has been identified at this time (GitHub Advisory, SailPoint).

Impact

Successful exploitation allows an unauthenticated attacker to access protected APIs and sensitive data managed by IdentityIQ, which as an identity governance platform may include user credentials, access entitlements, role assignments, and audit logs across connected enterprise systems. The CVSS assessment indicates high impact to confidentiality, integrity, and availability, meaning an attacker could read, modify, or disrupt identity data. Given IdentityIQ's role as a central identity and access management hub, compromise could facilitate lateral movement across connected enterprise applications and directories (GitHub Advisory, SailPoint).

Exploitability

As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment notes the vulnerability is not currently being exploited and is not fully automatable. The EPSS score is approximately 0.216%, placing it in the 12th percentile for exploitation likelihood within 30 days. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the disclosure date. Despite the low current exploitation evidence, the zero-privilege, network-accessible attack vector represents significant risk for exposed deployments.

Exploitation steps

  1. Reconnaissance: Identify internet-facing SailPoint IdentityIQ instances using tools such as Shodan or Censys, searching for IdentityIQ login pages or API endpoints (e.g., /identityiq/rest/).
  2. Identify target API endpoints: Enumerate protected REST API endpoints within IdentityIQ that require OAuth bearer token authentication (e.g., /identityiq/rest/identities, /identityiq/rest/roles).
  3. Craft or forge an OAuth bearer token: Construct a malformed, expired, or otherwise invalid OAuth bearer token that exploits the improper validation logic in IdentityIQ.
  4. Submit the crafted token: Send an HTTP request to a protected API endpoint with the forged token in the Authorization: Bearer <token> header.
  5. Access protected data: If the server improperly validates the token and grants access, retrieve sensitive identity governance data (user accounts, entitlements, roles, audit logs) or perform unauthorized modifications via the API (GitHub Advisory, SailPoint).

Indicators of compromise

  • Network: Unexpected or anomalous HTTP requests to IdentityIQ REST API endpoints (e.g., /identityiq/rest/) from unauthenticated or unknown source IPs; high volume of API requests without corresponding user session activity.
  • Logs: IdentityIQ application logs showing API access with malformed, expired, or structurally invalid OAuth bearer tokens that were nonetheless accepted; access log entries for protected API paths from IPs with no prior authentication history.
  • Logs: Unusual patterns of bulk data retrieval from identity or role management API endpoints outside of normal business hours or from unexpected geographic locations.
  • Process/Application: Unexpected changes to user accounts, role assignments, or access entitlements within IdentityIQ that cannot be attributed to authorized administrators or workflows.

Mitigation and workarounds

SailPoint has released a patch addressing this vulnerability; organizations should apply the security update available via the SailPoint security advisories page immediately (SailPoint). As interim mitigations, restrict network access to IdentityIQ API endpoints using firewall rules or network segmentation to limit exposure to trusted networks only. Organizations should also review OAuth token validation configurations, monitor API access logs for anomalous activity, and consider implementing additional authentication controls such as multi-factor authentication for API access where supported.

Additional resources


SourceThis report was generated using AI

Related SailPoint IdentityIQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12341CRITICAL9.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoJul 20, 2026
CVE-2024-10905CRITICAL9.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoYesDec 02, 2024
CVE-2026-5712HIGH8.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoApr 29, 2026
CVE-2024-2228HIGH8.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoYesMar 22, 2024
CVE-2025-10280MEDIUM6.1
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoNov 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management