CVE-2026-5712
published 2026-04-29CVE-2026-5712: This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the…
PriorityP349high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.16%
5.9th percentile
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sailpoint | identityiq | < 8.3 | 8.3 |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint_technologies | identityiq | >= 8.3 < 8.3p5 | 8.3p5 |
| sailpoint_technologies | identityiq | >= 8.4 < 8.4p4 | 8.4p4 |
| sailpoint_technologies | identityiq | >= 8.5 < 8.5p2 | 8.5p2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SailPoint IdentityIQ up to 8.3p4/8.4p3/8.5p1 authorization
vuldb·2026-04-29·CVSS 8.0
CVE-2026-5712 [HIGH] SailPoint IdentityIQ up to 8.3p4/8.4p3/8.5p1 authorization
A vulnerability was found in SailPoint IdentityIQ up to 8.3p4/8.4p3/8.5p1. It has been classified as problematic. This affects an unknown part. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2026-5712. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-77mr-jp79-jwp3: This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit th
ghsa_unreviewed·2026-04-29
CVE-2026-5712 [HIGH] CWE-863 GHSA-77mr-jp79-jwp3: This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit th
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-29
Published