CVE-2026-5712

Published Apr 29, 2026

Last updated 20 days ago

Overview

Description
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
Source
psirt@sailpoint.com
NVD status
Analyzed
Products
identityiq

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

psirt@sailpoint.com
CWE-863

Social media

Hype score
Not currently trending

Configurations