cbcvebase.
CVE-2026-5712
published 2026-04-29

CVE-2026-5712: This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the…

PriorityP349high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.16%
5.9th percentile
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

Affected

7 ranges
VendorProductVersion rangeFixed in
sailpointidentityiq< 8.38.3
sailpointidentityiq
sailpointidentityiq
sailpointidentityiq
sailpoint_technologiesidentityiq>= 8.3 < 8.3p58.3p5
sailpoint_technologiesidentityiq>= 8.4 < 8.4p48.4p4
sailpoint_technologiesidentityiq>= 8.5 < 8.5p28.5p2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.