# SailPoint IdentityIQ content-type XSS

Source: https://startwithidentity.com/cves/cve-2025-10280/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

IdentityIQ served a response with the wrong content-type and executed attacker-controlled script (CWE-79). CVSS 7.1. November 2025. SailPoint patched.

## Why it matters

XSS on an IGA console steals the session of the person who can change anyone's roles. That is [privilege escalation](https://startwithidentity.com/glossary/privilege-escalation/) via the browser, not via a connector.

## What to do

- Apply the November 2025 IdentityIQ fix.
- Enforce a strict CSP on the IIQ UI if you terminate TLS at a proxy that can set one.
- Prefer [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/) on every IGA admin, so a stolen session is shorter-lived.

## After you patch

A governance platform holds connector credentials into most of your estate and can grant access by design, which makes it a high-value target rather than a reporting tool.

- **Rotate every connector credential**, since these are typically privileged service accounts in the systems being governed.
- **Review entitlement changes, role assignments, and approvals** recorded during the exposure window, and re-verify any that lack a matching request.
- **Revoke sessions and API tokens** on the platform itself, and check for administrative accounts added during the window.
- **Re-run certification on privileged entitlements** rather than assuming the last campaign is still valid. See [access certification](https://startwithidentity.com/glossary/access-certification/) and [what is IGA](https://startwithidentity.com/guides/fundamentals/what-is-iga/).

## Sources

- [NVD: CVE-2025-10280](https://nvd.nist.gov/vuln/detail/CVE-2025-10280)
