SailPoint Technologies develops identity and access management platforms, with its vulnerability footprint concentrated in flagship products such as IdentityIQ and Desktop Password Reset, which serve as trust anchors for user provisioning and access control across enterprises. The recurring exposure patterns center on path traversal, privilege-management, and authorization weaknesses that arise from the boundary-crossing nature of identity systems—where trust decisions and file operations must interact securely across administrative and user contexts. Live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by SailPoint Technologies over time
Of all the CVEs published by SailPoint Technologies as a CNA, 64.3% affect products that SailPoint Technologies develops as a vendor.
Of all the CVEs published that affect products developed by SailPoint Technologies, 90.0% are self-published by SailPoint Technologies as a CNA.
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5712HIGH This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without | Apr 29, 2026 | 8.8 | 32 | NO | NO |
CVE-2024-10905CRITICAL IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prio | Dec 2, 2024 | 9.8 | 31 | NO | NO |
CVE-2023-32217HIGH IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jun 5, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-46835HIGH IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jan 31, 2023 | 7.5 | 25 | NO | NO |
CVE-2024-2228HIGH This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population. | Mar 22, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-45435MEDIUM IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8 | Jan 31, 2023 | 6.5 | 23 | NO | NO |
CVE-2024-2227HIGH This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2 | Mar 22, 2024 | 7.5 | 22 | NO | NO |
CVE-2019-12889HIGH An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to N | Aug 20, 2019 | 7.0 | 22 | NO | NO |
CVE-2025-10280MEDIUM IdentityIQ
8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and
all 8.3 patch levels including 8.3p5, and all prior versions allows some
IdentityIQ web s | Nov 3, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-1714HIGH An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by a | Feb 21, 2024 | 7.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by SailPoint Technologies.
Media articles that mention a CVE ID that affects a product developed by SailPoint Technologies — matched by CVE ID, not by vendor name.