# SailPoint ISC RCE via transform templates

Source: https://startwithidentity.com/cves/cve-2024-3319/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

ISC transform templates evaluated attacker-influenced expressions in a way that became code execution. SailPoint patched the SaaS side. Same class as [Conjur's Ruby template injection](https://startwithidentity.com/cves/cve-2025-49828/).

## Why it matters

Transforms are how IGA maps HR data onto accounts. Giving that language an eval is how a governance product becomes a foothold in the tenant that governs everyone else.

## What to do

- Confirm SailPoint's fix in your tenant.
- Restrict who can edit transforms. That permission is equivalent to code execution on the IGA plane.
- Review custom transforms for unexpected expressions after any contractor or high-priv session.

## After you patch

A governance platform holds connector credentials into most of your estate and can grant access by design, which makes it a high-value target rather than a reporting tool.

- **Rotate every connector credential**, since these are typically privileged service accounts in the systems being governed.
- **Review entitlement changes, role assignments, and approvals** recorded during the exposure window, and re-verify any that lack a matching request.
- **Revoke sessions and API tokens** on the platform itself, and check for administrative accounts added during the window.
- **Re-run certification on privileged entitlements** rather than assuming the last campaign is still valid. See [access certification](https://startwithidentity.com/glossary/access-certification/) and [what is IGA](https://startwithidentity.com/guides/fundamentals/what-is-iga/).

## Sources

- [NVD: CVE-2024-3319](https://nvd.nist.gov/vuln/detail/CVE-2024-3319)
