CVE-2026-12341: Sailpoint Identityiq
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
Affected products
- Sailpoint Identityiq: before 8.3 (fixed in 8.3); version 8.3 only; version 8.4 only; version 8.5 only
Published 2026-07-20. Last modified 2026-07-30.