{"record":"SailPoint evidence record","url":"https://nexalign.io/vendors/sailpoint","vendor":{"slug":"sailpoint","name":"SailPoint","domain":"sailpoint.com","category":"iam","categoryLabel":"Identity and access management"},"lastChecked":"2026-07-17T10:25:09.732Z","coverage":{"earliest":"2019-08-20T12:00:13.000Z","latest":"2026-07-17T10:25:09.732Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":19,"kindsOfSource":2,"attributedAdvisories":13,"knownExploited":0,"registerEntriesNotAttributable":1,"practitionerThreads":0,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":14,"latest":"2026-04-29T17:18:27.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":5,"latest":"2026-07-17T10:25:09.732Z"}],"advisories":{"shown":6,"total":13,"truncated":true,"fullList":"https://nexalign.io/vendors/sailpoint/advisories","items":[{"id":"CVE-2026-5712","description":"This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having…","severity":"high","cvss":8,"knownExploited":false,"date":"2026-04-29T17:18:27.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26260"]},{"id":"CVE-2026-4857","description":"IdentityIQ 8.5, all\nIdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ\n8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug\nPages Read…","severity":"high","cvss":8.4,"knownExploited":false,"date":"2026-04-15T18:08:45.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23007"]},{"id":"CVE-2025-10280","description":"IdentityIQ\n8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and\nall 8.3 patch levels including 8.3p5, and all prior versions allows some\nIdentityIQ web services…","severity":"high","cvss":7.1,"knownExploited":false,"date":"2025-11-03T16:35:56.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-37503"]},{"id":"CVE-2024-10905","description":"IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior…","severity":"critical","cvss":10,"knownExploited":false,"date":"2024-12-02T14:49:51.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-33546"]},{"id":"CVE-2024-3317","description":"An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque…","severity":"medium","cvss":6.5,"knownExploited":false,"date":"2024-05-15T15:55:07.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31907"]},{"id":"CVE-2024-3318","description":"A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including…","severity":"medium","cvss":4.2,"knownExploited":false,"date":"2024-05-15T15:49:36.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31908"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"SailPoint Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/identity-governance-administration/vendor/sailpoint","date":null},{"title":"SailPoint Identity Security Cloud Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/sailpoint-identity-security-cloud","date":null},{"title":"SailPoint Identity Security Cloud Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/identity-governance-administration/vendor/sailpoint/product/identity-security-platform","date":null},{"title":"SailPoint Reviews, Ratings & Features 2025 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/identity-governance-administration/vendor/sailpoint-technologies","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 1 register entries mention SailPoint without naming a product of SailPoint as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming SailPoint was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}