CVE-2026-5712SailPoint IdentityIQ role-editing authorization flaw
What broke
IdentityIQ did not enforce authorization on role editing. At disclosure (April 2026) the advisory applied to all versions. A user who could reach the feature could change roles outside their scope.
Why it matters
Roles are access in IGA. An authorization hole on role edit is a self-service privilege escalation with an audit trail that looks like a legitimate change.
What to do
- Apply SailPoint's April 2026 fix for your train.
- Diff roles and entitlements around the disclosure window. A new privileged role with no change-request is the hunt.
- Confirm SOD policies still fire on the patched build. Authz bugs sometimes skip those checks too.
After you patch
A governance platform holds connector credentials into most of your estate and can grant access by design, which makes it a high-value target rather than a reporting tool.
- Rotate every connector credential, since these are typically privileged service accounts in the systems being governed.
- Review entitlement changes, role assignments, and approvals recorded during the exposure window, and re-verify any that lack a matching request.
- Revoke sessions and API tokens on the platform itself, and check for administrative accounts added during the window.
- Re-run certification on privileged entitlements rather than assuming the last campaign is still valid. See access certification and what is IGA.
Sources
Related identity CVEs
Related on Start with Identity
- CVESailPoint IdentityIQ content-type XSS
IdentityIQ reflected script through an incorrect content-type (CWE-79). CVSS 7.1. November 2025. An XSS on an IGA console is an admin-session theft.
- CVESailPoint IdentityIQ directory traversal, CVSS 10.0
IdentityIQ exposed protected static content through improper access control and directory traversal. CVSS 10.0. Disclosed December 2024. e-fixes for 8.2p8, 8.3p
- CVESailPoint Identity Security Cloud access-control flaw
Identity Security Cloud (ISC) failed an access-control check. One of three 2024 ISC CVEs (3317/3318/3319) that still shape how we talk about SaaS IGA risk in 20
- BlogAgent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The
- BlogAgentic AI Identity Is the Next Frontier (And Your IAM Stack Isn't Ready)
AI agents now act on behalf of users, call APIs, and chain tools together. They need identities, scopes, and audit trails, and almost no existing IAM stack was
- BlogCrowdStrike agrees to buy SGNL for 740 million dollars
The deal that opened 2026's consolidation wave. SGNL brings CAEP-based continuous access evaluation and just-in-time authorization to a Falcon identity business