Identity and access management
SailPoint advisories: every record the registers tie to its products
In one line
13 advisories are attributed to SailPoint products in this record, covering January 2023 to April 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 1 register entry mentions SailPoint without naming one of its products as affected, and is excluded rather than counted. Each entry below links to the register that published it.
Attributed
13
tied to a named product
Known exploited
0
in the CISA catalogue
Rated critical
4
by the register
Last checked
Jul 17, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of SailPoint, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
1 entry did not clear that bar and is not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
13 of the 13 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- CVE-2026-5712highCVSS 8.0Apr 29, 2026
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having…
- CVE-2026-4857highCVSS 8.4Apr 15, 2026
IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read…
- CVE-2025-10280highCVSS 7.1Nov 03, 2025
IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services…
- CVE-2024-10905criticalCVSS 10.0Dec 02, 2024
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior…
- CVE-2024-3317mediumCVSS 6.5May 15, 2024
An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque…
- CVE-2024-3318mediumCVSS 4.2May 15, 2024
A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including…
- CVE-2024-3319criticalCVSS 9.1May 15, 2024
An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined…
- CVE-2024-2228highCVSS 7.1Mar 22, 2024
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
- CVE-2024-2227criticalCVSS 10.0Mar 22, 2024
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.
- CVE-2024-1714highCVSS 7.1Feb 21, 2024
An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an…
- CVE-2023-32217criticalCVSS 9.0May 31, 2023
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and…
- CVE-2022-46835highCVSS 8.8Jan 31, 2023
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and…
- CVE-2022-45435mediumCVSS 6.8Jan 31, 2023
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and…
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 14 | Apr 29, 2026 |
The entry counts here are the raw register totals for SailPoint, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does SailPoint have?
13 advisories in this record are tied by a register to a product of SailPoint. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any SailPoint vulnerabilities being actively exploited?
None of the 13 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.
Why does this page show fewer CVEs for SailPoint than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 1 register entry names SailPoint without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the SailPoint advisories on this page come from?
From European Vulnerability Database (ENISA, European Union). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean SailPoint is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
The full SailPoint record, including sources and open questions
