Start with Identity
Identity CVE · IGA

CVE-2025-10280SailPoint IdentityIQ content-type XSS

high · CVSS 7.1
Product: SailPoint IdentityIQVendor: SailPointCWE-79Disclosed: 2025-11-05Status: PatchedNVD ↗

What broke

IdentityIQ served a response with the wrong content-type and executed attacker-controlled script (CWE-79). CVSS 7.1. November 2025. SailPoint patched.

Why it matters

XSS on an IGA console steals the session of the person who can change anyone's roles. That is privilege escalation via the browser, not via a connector.

What to do

  • Apply the November 2025 IdentityIQ fix.
  • Enforce a strict CSP on the IIQ UI if you terminate TLS at a proxy that can set one.
  • Prefer phishing-resistant MFA on every IGA admin, so a stolen session is shorter-lived.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.