SailPoint Technologies
Self-Reporting Analysis
Of all the CVEs published by SailPoint Technologies as a CNA, 64.3% affect products that SailPoint Technologies develops as a vendor.
Of all the CVEs published that affect products developed by SailPoint Technologies, 90.0% are self-published by SailPoint Technologies as a CNA.
Trends Over Time
The number and severity of CVEs published by SailPoint Technologies over time
Top CVEs
All CVEs published by SailPoint Technologies as a CNA, regardless of affected vendor or product.
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12341HIGH This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bear | Jul 20, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-5712HIGH This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without | Apr 29, 2026 | 8.8 | 32 | NO | NO |
CVE-2024-10905CRITICAL IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prio | Dec 2, 2024 | 9.8 | 31 | NO | NO |
CVE-2026-4857HIGH IdentityIQ 8.5, all
IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ
8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug
Page | Apr 15, 2026 | 8.4 | 27 | NO | NO |
CVE-2024-3319CRITICAL An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user | May 15, 2024 | 9.1 | 25 | NO | NO |
CVE-2023-32217HIGH IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jun 5, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-46835HIGH IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jan 31, 2023 | 7.5 | 25 | NO | NO |
CVE-2024-2228HIGH This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population. | Mar 22, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-45435MEDIUM IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jan 31, 2023 | 6.5 | 23 | NO | NO |
CVE-2024-2227HIGH This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2 | Mar 22, 2024 | 7.5 | 22 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (14 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by SailPoint Technologies as a CNA.
Media Mentions
Media articles that mention a CVE ID published by SailPoint Technologies as a CNA — matched by CVE ID, not by organization name.