CVE-2026-5712
high
CVSS v3
8.8
CVSS v2
—
VIR risk
8.8
Description
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@sailpoint.com — https://www.sailpoint.com/security-advisories/sailpoint-identityiq-role-editor-incorrect-authorization-vulnerability-cve-2026-5712
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| sailpoint | identityiq | {"endExcluding":"8.3"} | 8.3 |
| sailpoint | identityiq | 8.3 | |
| sailpoint | identityiq | 8.4 | |
| sailpoint | identityiq | 8.5 | |
References
CWEs
CWE-863
Verify integrity in audit chain (admin only). AS-IS.