← Back

CVE-2026-5712

nvd nist
Published: Apr 29, 2026Modified: May 5, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

Affected (10)

1 product
Identityiq
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Sailpoint
Before 8.3
Version 8.3
Version 8.3 patch1
Version 8.3 patch2
Version 8.3 patch4
Version 8.4
Version 8.4 patch1
Version 8.4 patch2
Version 8.5
Version 8.5 patch1

Timeline

No history available yet.