CVE-2024-3317: Sailpoint Identity Security Cloud

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.

Affected products

  • Sailpoint Identity Security Cloud: affected versions not specified

Published 2024-05-15. Last modified 2026-06-17.