8
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Description
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
Basic Information
ID
CVE-2026-5712
Source
SailPoint
Published
Apr 29, 2026 at 17:18
Modified
Apr 29, 2026 at 18:12
Affected Product
Vendor
SailPoint Technologies
Product
IdentityIQ
Version
8.5
Affected Versions
SailPoint Technologies IdentityIQ 8.5
SailPoint Technologies IdentityIQ 8.4
SailPoint Technologies IdentityIQ 8.3
SailPoint Technologies IdentityIQ 8.4
SailPoint Technologies IdentityIQ 8.3