CVE-2026-5712: IdentityIQ Role Editor Incorrect Authorization Vulnerability
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5712?
CVE-2026-5712 is classified as a medium severity vulnerability due to its potential impact on role definitions.
How do I fix CVE-2026-5712?
To fix CVE-2026-5712, ensure that proper role editing permissions are enforced for users within IdentityIQ.
Who is affected by CVE-2026-5712?
CVE-2026-5712 affects all versions of SailPoint IdentityIQ where authentication mechanisms are improperly configured.
What specific impact does CVE-2026-5712 have on IdentityIQ?
CVE-2026-5712 allows unauthorized users to modify role definitions, potentially leading to privilege escalation.
Can unprivileged users exploit CVE-2026-5712?
Yes, authenticated users can exploit CVE-2026-5712 to edit role definitions without necessary permissions.