SailPoint IdentityIQ Debug UI Incorrect Authorization Vulnerability

Vulnerability

An incorrect authorization vulnerability has been identified in SailPoint IdentityIQ versions 8.5 (all patch levels prior to 8.5p2) and 8.4 (all patch levels prior to 8.4p4). This vulnerability allows authenticated users with the Debug Pages Read Only capability or any custom capability that includes the ViewAccessDebugPageSPRight to improperly create new IdentityIQ objects. Until a security fix is applied, the Debug Pages Read Only capability and any custom capabilities containing the ViewAccessDebugPageSPRight should be removed from all identities and workgroups.

Impact

Exploitation of this vulnerability could lead to unauthorized creation of IdentityIQ objects, potentially allowing for manipulation or misuse of identity data and application functionality.

Remediation

SailPoint has released a patch for this vulnerability in the SailPoint IdentityIQ 8.5p2 and 8.4p4 versions. Users should update to these versions to address the vulnerability.

Added: Apr 15, 2026, 7:34 PM
Updated: Apr 15, 2026, 7:34 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
4.9
remediation
8.3
relevance
6.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.