Identity CVE · IGA
CVE-2026-5712SailPoint IdentityIQ role-editing authorization flaw
high
What broke
IdentityIQ did not enforce authorization on role editing. At disclosure (April 2026) the advisory applied to all versions. A user who could reach the feature could change roles outside their scope.
Why it matters
Roles are access in IGA. An authorization hole on role edit is a self-service privilege escalation with an audit trail that looks like a legitimate change.
What to do
- Apply SailPoint's April 2026 fix for your train.
- Diff roles and entitlements around the disclosure window. A new privileged role with no change-request is the hunt.
- Confirm SOD policies still fire on the patched build. Authz bugs sometimes skip those checks too.
Sources
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.