Description
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
Published: 2026-07-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SailPoint IdentityIQ has a flaw in OAuth bearer token validation that lets an unauthenticated attacker send a forged or missing token to protected API endpoints and receive a valid authentication response. This bypass of authentication controls is classified as CWE‑287 and can expose confidential data to a non‑authorized client, potentially leading to a leak of privileged information.

Affected Systems

All versions of SailPoint IdentityIQ released by SailPoint Technologies are affected. No specific patch version ranges are listed, so any deployment of the product may be vulnerable unless a security update has been applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is less than 1%, suggesting a low probability that attackers are currently exploiting the flaw. The issue is not in the CISA KEV catalog. Attackers would likely target exposed API surface areas by presenting a crafted bearer token that the system erroneously accepts, enabling them to access protected resources without authentication.

Generated by OpenCVE AI on July 30, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest SailPoint IdentityIQ security patch that corrects bearer token validation.
  • Configure the IdentityIQ instance to enforce strict OAuth token validation, rejecting tokens that lack a proper signature or required claims.
  • Ensure that all API endpoints require authenticated access, apply rate limiting, and monitor logs for unusual bearer token usage.

Generated by OpenCVE AI on July 30, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Sailpoint Technologies
Sailpoint Technologies identityiq
Vendors & Products Sailpoint Technologies
Sailpoint Technologies identityiq

Mon, 20 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
Title SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Sailpoint Technologies Identityiq
cve-icon MITRE

Status: PUBLISHED

Assigner: SailPoint

Published:

Updated: 2026-07-21T12:32:33.109Z

Reserved: 2026-06-15T16:30:50.611Z

Link: CVE-2026-12341

cve-icon Vulnrichment

Updated: 2026-07-21T12:32:28.912Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:45:06Z

Weaknesses