CVE-2026-12341
SailPoint · IdentityIQ
SailPoint IdentityIQ is vulnerable to unauthorized API access due to improper validation of OAuth bearer tokens, allowing unauthenticated attackers to retrieve protected data.
Executive summary
A critical authentication bypass in SailPoint IdentityIQ allows unauthenticated attackers to access sensitive APIs and data.
Vulnerability
The application fails to properly validate OAuth bearer tokens, which permits unauthenticated actors to interact with protected APIs and gain unauthorized access to sensitive identity information.
Business impact
This vulnerability poses a severe risk to organizational security, as it directly impacts identity and access management systems. With a CVSS score of 8.8, the ability for an unauthenticated attacker to bypass authentication mechanisms could result in large-scale data exfiltration and complete loss of confidentiality regarding user identities and permissions.
Remediation
Immediate Action: Apply the vendor-supplied security patches or updates as outlined in the latest SailPoint security advisory.
Proactive Monitoring: Review API access logs for anomalous traffic patterns or unauthorized requests originating from unknown or suspicious sources.
Compensating Controls: Restrict access to the IdentityIQ API to known, trusted IP ranges and ensure that network-level access controls are strictly enforced.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the central role of IdentityIQ in enterprise security, this vulnerability must be treated with extreme urgency. Administrators should prioritize the application of vendor patches to protect the integrity and confidentiality of the identity management environment.