Home

Description

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

PUBLISHED Reserved 2026-04-06 | Published 2026-04-29 | Updated 2026-04-30 | Assigner SailPoint




HIGH: 8.0CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-863: Incorrect Authorization

Product status

Default status
affected

8.5 (custom) before 8.5p2
affected

8.4 (custom) before 8.4p4
affected

8.3 (custom) before 8.3p5
affected

Credits

wildwildwes reporter

References

www.sailpoint.com/...thorization-vulnerability-cve-2026-5712

cve.org (CVE-2026-5712)

nvd.nist.gov (CVE-2026-5712)

Download JSON