CVE-2026-12341EPSS p31.6%

CVE-2026-12341CVE-2026-12341

sailpoint / identityiq

Description

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.

Scoring

CVSS 8.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.40% probability of exploitation · percentile 31.6% · 2026-10-06T12:00:23Z
Last modified2026-07-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.