# SailPoint Identity Security Cloud access-control flaw

Source: https://startwithidentity.com/cves/cve-2024-3317/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

SailPoint Identity Security Cloud did not enforce an access-control check. CVE-2024-3317 is the access-control ID in a three-bug set with [connector path traversal](https://startwithidentity.com/cves/cve-2024-3318/) and [RCE via transform templates](https://startwithidentity.com/cves/cve-2024-3319/). SailPoint patched the SaaS side.

## Why it matters

SaaS IGA feels like "SailPoint will patch it." The customer still has to rotate connectors, review who can edit transforms, and treat ISC like the privileged system it is. We keep the 2024 ISC set in this catalog because the 2025-2026 IdentityIQ bugs are the same story on-prem.

## What to do

- Confirm SailPoint applied the ISC fix in your tenant. SaaS patches are not always simultaneous.
- Review API tokens and admin roles in ISC the way you would after an IdP incident.

## After you patch

A governance platform holds connector credentials into most of your estate and can grant access by design, which makes it a high-value target rather than a reporting tool.

- **Rotate every connector credential**, since these are typically privileged service accounts in the systems being governed.
- **Review entitlement changes, role assignments, and approvals** recorded during the exposure window, and re-verify any that lack a matching request.
- **Revoke sessions and API tokens** on the platform itself, and check for administrative accounts added during the window.
- **Re-run certification on privileged entitlements** rather than assuming the last campaign is still valid. See [access certification](https://startwithidentity.com/glossary/access-certification/) and [what is IGA](https://startwithidentity.com/guides/fundamentals/what-is-iga/).

## Sources

- [NVD: CVE-2024-3317](https://nvd.nist.gov/vuln/detail/CVE-2024-3317)
