Sentry
38 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Sentry, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Sentry CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 2 |
| 2024-11 | 1 |
| 2024-12 | 1 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 2 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 2 |
| 2026-06 | 3 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 2 |
Severity
How the 38 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical9
- High16
- Medium10
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Sentry.
- CVE-2026-83803Sentry: Unsafe pickle deserialization in Relocation Feature—
- CVE-2026-83527An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.8.1
- CVE-2026-52794Sentry: Inefficient Regular Expression Complexity in sentry7.5
- CVE-2026-10523An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative ...9.9
- CVE-2026-10520An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution10.0
- CVE-2021-47935Sentry 8.2.0 Remote Code Execution via Pickle Deserialization8.8
- CVE-2026-42354Sentry: Improper authentication on SAML SSO process allows user identity linking9.1
- CVE-2026-26004Sentry allows unauthorized access to event data across organizational boundaries6.5
- CVE-2026-27197Sentry: Improper Authentication on SAML SSO process allows user identity linking9.1
- CVE-2023-39338Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry policy to access that service. It does not enable the...6.8
- CVE-2025-53099Sentry Missing Invalidation of Authorization Codes During OAuth Exchange and Revocation7.5
- CVE-2025-53073In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's ...4.2
- CVE-2025-22146Improper authentication on SAML SSO process allows user impersonation in sentry9.1
- CVE-2024-8540Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.8.8
- CVE-2024-53253Sentry's improper error handling leaks Application Integration Client Secret5.3
Product grouping is registry-driven, with AI assist and human review. How it works