SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability – CVE-2026-12341
Description
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
Affected product and versions
- IdentityIQ 8.5 and all 8.5 patch levels through 8.5p1
- IdentityIQ 8.4 and all 8.4 patch levels through 8.4p4
- IdentityIQ 8.3 and all 8.3 patch levels through 8.3p5
- All previous versions are affected
Resolution
SailPoint has released IIQSR-982 for each impacted and supported version of IdentityIQ. Future patch levels will include the fixes once they become available.
CVE details
CVE ID: CVE-2026-12341
Published Date: 07/20/2026
Vulnerability Type: IdentityIQ Improper Bearer Token Validation Vulnerability
CWE: CWE-287
CVSS v3 Score: 8.8
CVSS v3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H