CVE-2026-12341
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data
CVSS
8.8
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 20 jul 2026 · Última mod.: 20 jul 2026 · CWE-287
Sin historial EPSS suficiente todavía.
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-468179.8 CRÍ60.4%
KEV—68Oracle E-Business Suite Improper Privilege Management Vulnerability2hCVE-2023-278239.8 CRÍ98.9%
——30An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.12dCVE-2022-470039.8 CRÍ88.2%
——26A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.12dCVE-2026-242947.8 ALT84.7%
——25Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.20dCVE-2020-288747.5 ALT81.8%
——25reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).12dCVE-2022-233207.5 ALT73.6%
——22XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.12d