Impact
SailPoint IdentityIQ has a flaw in OAuth bearer token validation that lets an unauthenticated attacker send a forged or missing token to protected API endpoints and receive a valid authentication response. This bypass of authentication controls is classified as CWE‑287 and can expose confidential data to a non‑authorized client, potentially leading to a leak of privileged information.
Affected Systems
All versions of SailPoint IdentityIQ released by SailPoint Technologies are affected. No specific patch version ranges are listed, so any deployment of the product may be vulnerable unless a security update has been applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is less than 1%, suggesting a low probability that attackers are currently exploiting the flaw. The issue is not in the CISA KEV catalog. Attackers would likely target exposed API surface areas by presenting a crafted bearer token that the system erroneously accepts, enabling them to access protected resources without authentication.
OpenCVE Enrichment