External risk intelligence

SailPoint IdentityIQ Improper OAuth Token Validation Leads to Unauthorized API Access

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-12341

SailPoint IdentityIQ is an identity governance platform that often includes web-based portals and API endpoints designed to be accessible to users and integrated systems, frequently deployed in configurations that allow external or broad network reachability to facilitate identity management and authentication workflows.

Authentication Bypass

Sailpoint Identityiq

before 8.38.38.48.5

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security issue has been identified in SailPoint IdentityIQ that could allow unauthorized access to sensitive data and protected APIs due to improper handling of security tokens. This vulnerability could have significant implications for data confidentiality and integrity within affected systems.

  • Unauthenticated attackers may gain unauthorized access.
  • This issue affects core identity and access controls.
  • Confirm relevance and assess exposure to protected data.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach protected APIs and sensitive data by exploiting a flaw in how IdentityIQ validates OAuth bearer tokens. This allows unauthorized access, potentially leading to significant data compromise and system control.

  • No authentication required to start.
  • Improper OAuth token validation.
  • Unauthorized API and data access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to access protected APIs and sensitive data within IdentityIQ by bypassing authentication due to improper handling of OAuth bearer tokens.

  • Protected APIs and data at risk.
  • Exploits improper OAuth token validation.
  • Unauthorized access to system information.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical nature of this vulnerability in SailPoint IdentityIQ, which exposes protected APIs and data due to improper OAuth token validation, necessitates immediate attention from teams responsible for identity governance and the underlying infrastructure. The first practical step is to locate all instances of IdentityIQ within the environment, ascertain their network exposure and business criticality, identify the designated system owner, and then prioritize remediation efforts based on these findings.

  • Identity and infrastructure teams own this.
  • Verify IdentityIQ network exposure and criticality.
  • Plan risk-based remediation with the vendor.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SailPoint IdentityIQ?

SailPoint IdentityIQ is an identity governance platform used by organizations to manage and secure digital identities across the enterprise. It centralizes control over user access rights, automates lifecycle processes, and provides web-based portals and API endpoints. These features allow it to integrate deeply with various IT systems, managing authentication workflows and ensuring that employees have the correct permissions for the applications and data they need to perform their jobs.

What does CVE-2026-12341 mean?

This vulnerability involves a weakness classified as Improper Authentication (CWE-287). In plain English, the system fails to correctly verify the identity of someone trying to connect via an OAuth bearer token. Because the software does not properly check these digital credentials, it may mistakenly grant access to someone who is not authorized. This effectively lets an outsider interact with protected APIs and sensitive data as if they were a legitimate, logged-in user.

How does an attacker trigger this vulnerability?

The flaw is triggered when an attacker sends requests to protected APIs without providing valid, properly verified OAuth tokens. Because the system's validation logic is bypassed, it accepts the unauthorized request. Importantly, this does not require the attacker to have any existing credentials or account access to the system beforehand; the vulnerability exists because the software fails to perform the necessary verification steps for incoming connections entirely.

Is my IdentityIQ instance at risk?

According to Halo Surface Signal, you should be concerned if your IdentityIQ deployment is reachable via the internet or broad network segments. Because the platform's design often necessitates web-based access for users and integrated systems, it is frequently placed in locations where it can be reached externally. If your instance is configured with such network reachability, it is considered a high-priority target for this specific unauthorized access vulnerability.

What are the first steps to address this?

Start by identifying all instances of IdentityIQ running in your environment and confirm their current network exposure. Work with the designated system owners to assess the business criticality of each instance. Once you have an inventory, prepare to implement the vendor's recommended security updates. Prioritize patching based on whether the specific instance is accessible over the network, ensuring that the most exposed systems are addressed first.

References