# SailPoint ISC connector path traversal

Source: https://startwithidentity.com/cves/cve-2024-3318/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

An ISC connector accepted a path it should have rejected and read or wrote outside the intended file set. SailPoint patched. This is the closest thing the 2025-2026 window had to a [SCIM](https://startwithidentity.com/glossary/scim/) / provisioning CVE: not the protocol, the connector.

## Why it matters

Provisioning connectors hold service credentials to AD, Entra, HR, and SaaS. A path traversal there is how an IGA admin (or an attacker who became one) reads those credentials off disk.

## What to do

- Confirm the ISC connector fix in your tenant.
- Rotate connector service accounts. Treat them as tier-zero.
- Do not let custom connector code read arbitrary paths "for debugging."

## After you patch

Provisioning interfaces create and modify accounts, so a flaw here is an account-creation primitive rather than a data leak.

- **Rotate the SCIM bearer token or client credential** used by the identity provider.
- **Reconcile provisioned accounts against the authoritative source** and remove anything with no matching identity. See [orphaned account](https://startwithidentity.com/glossary/orphaned-account/).
- **Review group membership changes** applied through the connector during the window.
- **Confirm deactivation semantics**: verify that `active: false` actually removes access in the target application rather than soft-deleting a still-usable account. See [SCIM 2.0](https://startwithidentity.com/standards/scim-2-0/).

## Sources

- [NVD: CVE-2024-3318](https://nvd.nist.gov/vuln/detail/CVE-2024-3318)
