
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5712 is an incorrect authorization vulnerability in SailPoint IdentityIQ that allows an authenticated user who is the requestor or assignee of a work item to edit role definitions without possessing the required role-editing capability. The vulnerability affects all versions of IdentityIQ, including versions prior to 8.3, 8.3 through patch 4, 8.4 through patch 2, and 8.5 through patch 1. It was published on April 29, 2026, with patches made available by SailPoint. The CVSS v3.1 base score is 8.8 (High) per NVD, while the GitHub Advisory Database rates it 8.0 (High) (GitHub Advisory, SailPoint Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization), meaning the application performs an authorization check when a user attempts to perform an action, but does not correctly enforce it. Specifically, IdentityIQ fails to properly validate whether a user has the required capability to edit role definitions when that user is acting as a requestor or assignee of a work item. An authenticated attacker with low privileges can exploit this by leveraging their work item context to submit role definition modifications that the application should otherwise reject. No public proof-of-concept code has been identified at this time (GitHub Advisory, SailPoint Advisory).
Successful exploitation allows authenticated attackers to escalate their effective privileges by modifying role definitions within IdentityIQ's identity governance framework without authorization. An attacker could alter role definitions to grant themselves or other identities elevated permissions, bypass access controls, or undermine the integrity of identity management policies across the organization. Given that IdentityIQ is a central identity governance platform, unauthorized role modifications could have cascading effects on access control decisions across connected enterprise systems, posing high risks to confidentiality, integrity, and availability (SailPoint Advisory, GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.036% (0.000360), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with access to work items, limiting the attack surface to insiders or compromised accounts (GitHub Advisory, SailPoint Advisory).
RoleModified or equivalent audit actions) initiated by accounts that do not hold role-editing capabilities; unexpected role edit activity associated with work item requestor or assignee accounts.SailPoint has released patches addressing this vulnerability: organizations should upgrade to IdentityIQ 8.3 patch 5 or later, 8.4 patch 4 or later, or 8.5 patch 2 or later. As an interim measure, administrators should implement enhanced monitoring and logging of role definition modifications to detect unauthorized changes, and audit user access rights to role-editing capabilities, removing unnecessary permissions. Additionally, restricting work item requestor and assignee roles to trusted accounts only can limit the scope of potential exploitation until patching is complete (SailPoint Advisory, GitHub Advisory).
Coverage of CVE-2026-5712 has been limited to standard vulnerability aggregation and tracking platforms, with no notable independent researcher commentary or significant social media discussion identified. The vulnerability was noted on Bluesky by cybersecurity community accounts shortly after disclosure. No major media coverage or vendor statements beyond SailPoint's own advisory have been observed (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."