CVE-2026-5712
8.0SailPoint Technologies · IdentityIQ
An incorrect authorization vulnerability in SailPoint IdentityIQ allows authenticated users to modify role definitions without the required privileges.
Executive summary
A critical authorization flaw in SailPoint IdentityIQ allows authenticated users to escalate their privileges by modifying role definitions, potentially compromising system access controls.
Vulnerability
The vulnerability is an instance of CWE-863 (Incorrect Authorization) where an authenticated identity acting as a requestor or assignee of a work item can bypass capability checks to edit role definitions. This flaw allows users to perform unauthorized administrative actions despite lacking the necessary permissions.
Business impact
The ability for non-privileged users to edit role definitions represents a significant security risk, as it allows for the manipulation of identity and access management policies. Successful exploitation could lead to unauthorized privilege escalation, granting attackers access to sensitive resources or systems that they are not entitled to manage. Given the CVSS score of 8.0, this high-severity vulnerability poses a substantial threat to the integrity and confidentiality of the entire enterprise identity infrastructure.
Remediation
Immediate Action: Apply the vendor-supplied security patches for the affected versions (8.5p2, 8.4p4, or 8.3p5, depending on your current deployment) immediately.
Proactive Monitoring: Review IdentityIQ audit logs for unusual modifications to role definitions, specifically focusing on changes initiated by users who do not possess the appropriate administrative capabilities.
Compensating Controls: Restrict work item access and enforce the principle of least privilege for all identities within the IdentityIQ platform to limit the potential blast radius of a compromised account.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing SailPoint IdentityIQ must prioritize the deployment of the provided patches to prevent unauthorized role modifications. Given that this vulnerability bypasses standard capability checks, failing to patch could allow malicious or compromised internal actors to escalate their permissions significantly. Initiate your patch management process immediately to ensure the integrity of your identity governance environment.
More SailPoint Technologies CVEs
Sources
Originally found and disclosed by wildwildwes, per the CVE Program record.