CVE-2026-12341

SailPoint · IdentityIQ

SailPoint IdentityIQ is vulnerable to unauthorized API access due to improper validation of OAuth bearer tokens, allowing unauthenticated attackers to retrieve protected data.

Executive summary

A critical authentication bypass in SailPoint IdentityIQ allows unauthenticated attackers to access sensitive APIs and data.

Vulnerability

The application fails to properly validate OAuth bearer tokens, which permits unauthenticated actors to interact with protected APIs and gain unauthorized access to sensitive identity information.

Business impact

This vulnerability poses a severe risk to organizational security, as it directly impacts identity and access management systems. With a CVSS score of 8.8, the ability for an unauthenticated attacker to bypass authentication mechanisms could result in large-scale data exfiltration and complete loss of confidentiality regarding user identities and permissions.

Remediation

Immediate Action: Apply the vendor-supplied security patches or updates as outlined in the latest SailPoint security advisory.

Proactive Monitoring: Review API access logs for anomalous traffic patterns or unauthorized requests originating from unknown or suspicious sources.

Compensating Controls: Restrict access to the IdentityIQ API to known, trusted IP ranges and ensure that network-level access controls are strictly enforced.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the central role of IdentityIQ in enterprise security, this vulnerability must be treated with extreme urgency. Administrators should prioritize the application of vendor patches to protect the integrity and confidentiality of the identity management environment.