CVE-2025-10280SailPoint IdentityIQ content-type XSS
What broke
IdentityIQ served a response with the wrong content-type and executed attacker-controlled script (CWE-79). CVSS 7.1. November 2025. SailPoint patched.
Why it matters
XSS on an IGA console steals the session of the person who can change anyone's roles. That is privilege escalation via the browser, not via a connector.
What to do
- Apply the November 2025 IdentityIQ fix.
- Enforce a strict CSP on the IIQ UI if you terminate TLS at a proxy that can set one.
- Prefer phishing-resistant MFA on every IGA admin, so a stolen session is shorter-lived.
After you patch
A governance platform holds connector credentials into most of your estate and can grant access by design, which makes it a high-value target rather than a reporting tool.
- Rotate every connector credential, since these are typically privileged service accounts in the systems being governed.
- Review entitlement changes, role assignments, and approvals recorded during the exposure window, and re-verify any that lack a matching request.
- Revoke sessions and API tokens on the platform itself, and check for administrative accounts added during the window.
- Re-run certification on privileged entitlements rather than assuming the last campaign is still valid. See access certification and what is IGA.
Sources
Related identity CVEs
Related on Start with Identity
- CVESailPoint IdentityIQ directory traversal, CVSS 10.0
IdentityIQ exposed protected static content through improper access control and directory traversal. CVSS 10.0. Disclosed December 2024. e-fixes for 8.2p8, 8.3p
- CVESailPoint IdentityIQ role-editing authorization flaw
IdentityIQ failed to authorize role edits on all versions at disclosure (April 2026). Anyone who could reach the role-editing surface could change roles they sh
- CVESailPoint Identity Security Cloud access-control flaw
Identity Security Cloud (ISC) failed an access-control check. One of three 2024 ISC CVEs (3317/3318/3319) that still shape how we talk about SaaS IGA risk in 20
- VendorSailPoint
top_tier
- Comparisonsailpoint-vs-saviynt
SailPoint has the deepest connector coverage for legacy and mainframe estates. Saviynt is cloud-native with stronger out-of-the-box SaaS and cloud access govern
- Comparisonveza-vs-sailpoint
Veza and SailPoint both address identity governance, but they enter from different angles. SailPoint is the established enterprise IGA platform covering the ful