CVE-2024-3319SailPoint ISC RCE via transform templates
What broke
ISC transform templates evaluated attacker-influenced expressions in a way that became code execution. SailPoint patched the SaaS side. Same class as Conjur's Ruby template injection.
Why it matters
Transforms are how IGA maps HR data onto accounts. Giving that language an eval is how a governance product becomes a foothold in the tenant that governs everyone else.
What to do
- Confirm SailPoint's fix in your tenant.
- Restrict who can edit transforms. That permission is equivalent to code execution on the IGA plane.
- Review custom transforms for unexpected expressions after any contractor or high-priv session.
After you patch
A governance platform holds connector credentials into most of your estate and can grant access by design, which makes it a high-value target rather than a reporting tool.
- Rotate every connector credential, since these are typically privileged service accounts in the systems being governed.
- Review entitlement changes, role assignments, and approvals recorded during the exposure window, and re-verify any that lack a matching request.
- Revoke sessions and API tokens on the platform itself, and check for administrative accounts added during the window.
- Re-run certification on privileged entitlements rather than assuming the last campaign is still valid. See access certification and what is IGA.
Sources
Related identity CVEs
Related on Start with Identity
- CVESailPoint Identity Security Cloud access-control flaw
Identity Security Cloud (ISC) failed an access-control check. One of three 2024 ISC CVEs (3317/3318/3319) that still shape how we talk about SaaS IGA risk in 20
- CVESailPoint ISC connector path traversal
Identity Security Cloud connector configuration allowed path traversal. The 2025-2026 research notes that SCIM itself was quiet; provisioning risk sat in IdP an
- CVESailPoint IdentityIQ content-type XSS
IdentityIQ reflected script through an incorrect content-type (CWE-79). CVSS 7.1. November 2025. An XSS on an IGA console is an admin-session theft.
- VendorSailPoint
top_tier
- Comparisonsailpoint-vs-saviynt
SailPoint has the deepest connector coverage for legacy and mainframe estates. Saviynt is cloud-native with stronger out-of-the-box SaaS and cloud access govern
- Comparisonveza-vs-sailpoint
Veza and SailPoint both address identity governance, but they enter from different angles. SailPoint is the established enterprise IGA platform covering the ful