Protocol · 1 briefs
SCIM and provisioning identity CVEs
The SCIM protocol itself was quiet in 2025-2026. Provisioning risk sat in IdP and IGA connectors: path traversal, transform-template RCE, and the credentials those connectors hold.
How this protocol fails
Provisioning connectors hold service accounts to AD, Entra, HR, and SaaS. A path traversal or template injection there is how an IGA admin (or an attacker who became one) reads those credentials or runs code on the governance plane. SailPoint ISC 2024 is the worked example. There is no notable standalone SCIM protocol CVE in this catalog. That is not the same as "provisioning is safe."
What security people should do
- Rotate connector service accounts. Treat them as tier-zero.
- Restrict who can edit IGA transforms and connector file paths. That permission is equivalent to code execution.
- Prefer SCIM 2.0 over custom connectors where the SaaS supports it, then still lock down the client credentials.
CVEs in this category
1
SCIM / Provisioning
0
On CISA KEV
0
Actively exploited
1
Showing
Severity
Year
Status
Showing 1 of 1
Working this protocol in production and see a brief we should add or correct? Email [email protected] or volunteer as a CVE Analyst.