CVE-2026-12341
קריטית 9.8
תיאור (מקור, אנגלית)
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-2/8/2026
- CWE
- CWE-287
מוצרים מושפעים
sailpoint: identityiq
קישורים
- https://www.sailpoint.com/security-advisories/ Vendor Advisory