CVE-2026-5712
SailPoint IdentityIQ vulnerability analysis and mitigation

Overview

CVE-2026-5712 is an incorrect authorization vulnerability in SailPoint IdentityIQ that allows an authenticated user who is the requestor or assignee of a work item to edit role definitions without possessing the required role-editing capability. The vulnerability affects all versions of IdentityIQ, including versions prior to 8.3, 8.3 through patch 4, 8.4 through patch 2, and 8.5 through patch 1. It was published on April 29, 2026, with patches made available by SailPoint. The CVSS v3.1 base score is 8.8 (High) per NVD, while the GitHub Advisory Database rates it 8.0 (High) (GitHub Advisory, SailPoint Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization), meaning the application performs an authorization check when a user attempts to perform an action, but does not correctly enforce it. Specifically, IdentityIQ fails to properly validate whether a user has the required capability to edit role definitions when that user is acting as a requestor or assignee of a work item. An authenticated attacker with low privileges can exploit this by leveraging their work item context to submit role definition modifications that the application should otherwise reject. No public proof-of-concept code has been identified at this time (GitHub Advisory, SailPoint Advisory).

Impact

Successful exploitation allows authenticated attackers to escalate their effective privileges by modifying role definitions within IdentityIQ's identity governance framework without authorization. An attacker could alter role definitions to grant themselves or other identities elevated permissions, bypass access controls, or undermine the integrity of identity management policies across the organization. Given that IdentityIQ is a central identity governance platform, unauthorized role modifications could have cascading effects on access control decisions across connected enterprise systems, posing high risks to confidentiality, integrity, and availability (SailPoint Advisory, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.036% (0.000360), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with access to work items, limiting the attack surface to insiders or compromised accounts (GitHub Advisory, SailPoint Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target SailPoint IdentityIQ deployment running a vulnerable version (prior to 8.3p5, 8.4p4, or 8.5p2) and obtain or compromise a low-privileged authenticated account.
  2. Obtain Work Item Access: Ensure the attacker's account is either the requestor or assignee of an existing work item within IdentityIQ, which grants the exploitable context.
  3. Trigger Role Edit: Using the authenticated session, navigate to or craft a request targeting the role definition editor functionality, leveraging the work item context to bypass the capability authorization check.
  4. Modify Role Definition: Submit unauthorized changes to a role definition — such as adding elevated entitlements, expanding membership criteria, or granting additional permissions — that the account would not normally be permitted to make.
  5. Achieve Privilege Escalation: The modified role definition takes effect within IdentityIQ, potentially granting the attacker or other targeted identities elevated access across connected enterprise systems (SailPoint Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: IdentityIQ audit logs showing role definition modification events (RoleModified or equivalent audit actions) initiated by accounts that do not hold role-editing capabilities; unexpected role edit activity associated with work item requestor or assignee accounts.
  • Application Behavior: Role definitions changed without corresponding approval workflows or capability assignments visible in the audit trail; discrepancies between assigned capabilities and recorded role-editing actions in IdentityIQ audit reports.
  • Access Control Changes: Unexpected expansion of role entitlements or membership criteria in IdentityIQ roles, particularly for high-privilege roles; new or modified roles granting elevated access to previously low-privileged identities.
  • User Activity: Low-privileged accounts accessing role management UI endpoints or API calls associated with role definition editing outside of normal administrative workflows (SailPoint Advisory).

Mitigation and workarounds

SailPoint has released patches addressing this vulnerability: organizations should upgrade to IdentityIQ 8.3 patch 5 or later, 8.4 patch 4 or later, or 8.5 patch 2 or later. As an interim measure, administrators should implement enhanced monitoring and logging of role definition modifications to detect unauthorized changes, and audit user access rights to role-editing capabilities, removing unnecessary permissions. Additionally, restricting work item requestor and assignee roles to trusted accounts only can limit the scope of potential exploitation until patching is complete (SailPoint Advisory, GitHub Advisory).

Community reactions

Coverage of CVE-2026-5712 has been limited to standard vulnerability aggregation and tracking platforms, with no notable independent researcher commentary or significant social media discussion identified. The vulnerability was noted on Bluesky by cybersecurity community accounts shortly after disclosure. No major media coverage or vendor statements beyond SailPoint's own advisory have been observed (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related SailPoint IdentityIQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12341CRITICAL9.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoJul 20, 2026
CVE-2024-10905CRITICAL9.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoYesDec 02, 2024
CVE-2026-5712HIGH8.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoApr 29, 2026
CVE-2024-2228HIGH8.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoYesMar 22, 2024
CVE-2025-10280MEDIUM6.1
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoNov 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management