Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

SailPoint Technologies

First CVE: Aug 20, 2019Active for: 7 yearsTotal CVEs: 10
41.5
VTI Score
High

SailPoint Technologies develops identity and access management platforms, with its vulnerability footprint concentrated in flagship products such as IdentityIQ and Desktop Password Reset, which serve as trust anchors for user provisioning and access control across enterprises. The recurring exposure patterns center on path traversal, privilege-management, and authorization weaknesses that arise from the boundary-crossing nature of identity systems—where trust decisions and file operations must interact securely across administrative and user contexts. Live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by SailPoint Technologies over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2019
6 years ago
Most Recent CVE
Apr 29, 2026
86 days ago

Self-Reporting Analysis

Of all the CVEs published by SailPoint Technologies as a CNA, 64.3% affect products that SailPoint Technologies develops as a vendor.

64.3%
35.7%
Self-reported: 9 (64.3%)
Third-party: 5 (35.7%)

Of all the CVEs published that affect products developed by SailPoint Technologies, 90.0% are self-published by SailPoint Technologies as a CNA.

90.0%
Self-published: 9 (90.0%)
Other CNAs: 1 (10.0%)

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-5712HIGH
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without
Apr 29, 20268.832NONO
CVE-2024-10905CRITICAL
IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prio
Dec 2, 20249.831NONO
CVE-2023-32217HIGH
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8
Jun 5, 20238.825NONO
CVE-2022-46835HIGH
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8
Jan 31, 20237.525NONO
CVE-2024-2228HIGH
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
Mar 22, 20248.823NONO
CVE-2022-45435MEDIUM
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8
Jan 31, 20236.523NONO
CVE-2024-2227HIGH
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2
Mar 22, 20247.522NONO
CVE-2019-12889HIGH
An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to N
Aug 20, 20197.022NONO
CVE-2025-10280MEDIUM
IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web s
Nov 3, 20256.121NONO
CVE-2024-1714HIGH
An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by a
Feb 21, 20247.118NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
20%
70%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low6 (60.0%)
High0 (0.0%)
None4 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by SailPoint Technologies.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by SailPoint Technologies — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For SailPoint Technologies's Products

View all 2 CNAs →

Top CWEs