Start with Identity
Protocol · 5 briefs

IGA identity CVEs

Identity governance is where joiner-mover-leaver actually happens. A CVSS 10 on IdentityIQ or a role-edit authz hole is a path to every entitlement, not a web-app finding.

How this protocol fails

SailPoint IdentityIQ shipped a CVSS 10.0 static-content traversal (Dec 2024), XSS on the admin console (2025), and a role-editing authorization flaw on all versions (Apr 2026). ISC had access-control, connector path traversal, and transform-template RCE in 2024. Roles are access. An authorization hole on role edit looks like a legitimate change in the audit trail.

What security people should do

  • Apply SailPoint e-fixes by train. "We are on 8.4" is not the same as "we took the e-fix."
  • Take IdentityIQ off the internet. Put it behind SSO and an admin jump path.
  • Diff roles and entitlements around each disclosure window. A new privileged role with no change-request is the hunt.
  • Restrict who can edit transforms and connectors in ISC. That is code execution on the IGA plane.

CVEs in this category

5
IGA
0
On CISA KEV
0
Actively exploited
5
Showing
Severity
Year
Status

Showing 5 of 5

Working this protocol in production and see a brief we should add or correct? Email [email protected] or volunteer as a CVE Analyst.