# SailPoint IdentityIQ directory traversal, CVSS 10.0

Source: https://startwithidentity.com/cves/cve-2024-10905/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[SailPoint IdentityIQ](https://startwithidentity.com/vendors/iga/sailpoint/) served protected static content through a directory-traversal / access-control gap. CVSS 10.0. Disclosed December 2024. SailPoint shipped e-fixes for 8.2p8, 8.3p5, and 8.4p2.

## Why it matters

IGA is where joiner-mover-leaver actually happens. A CVSS 10 on IdentityIQ is not a web-app finding. It is a path to every entitlement model, every SOD rule, and often the service accounts IIQ uses to write to AD. We keep it in this catalog because 2025-2026 assessments still find unpatched 8.2/8.3.

## What to do

- Apply the e-fix for your train. Confirm with SailPoint's advisory, not with "we are on 8.4."
- Take IdentityIQ off the internet. Put it behind SSO and an admin jump path.
- Review the 2025-2026 follow-ons: [CVE-2025-10280](https://startwithidentity.com/cves/cve-2025-10280/) (XSS) and [CVE-2026-5712](https://startwithidentity.com/cves/cve-2026-5712/) (role-editing authz).

## After you patch

A governance platform holds connector credentials into most of your estate and can grant access by design, which makes it a high-value target rather than a reporting tool.

- **Rotate every connector credential**, since these are typically privileged service accounts in the systems being governed.
- **Review entitlement changes, role assignments, and approvals** recorded during the exposure window, and re-verify any that lack a matching request.
- **Revoke sessions and API tokens** on the platform itself, and check for administrative accounts added during the window.
- **Re-run certification on privileged entitlements** rather than assuming the last campaign is still valid. See [access certification](https://startwithidentity.com/glossary/access-certification/) and [what is IGA](https://startwithidentity.com/guides/fundamentals/what-is-iga/).

## Sources

- [NVD: CVE-2024-10905](https://nvd.nist.gov/vuln/detail/CVE-2024-10905)
- SailPoint e-fix advisories for IdentityIQ 8.2/8.3/8.4
