Exposure of Sentry

Issue trackers
85
exposure score
547,625
sites use
0
exploited
6
critical
Vexday analysis

O histórico de vulnerabilidades do Sentry reúne 26 CVEs catalogadas, das quais 6 são de severidade crítica e 5 surgiram nos últimos 90 dias, indicando um ritmo recente de descobertas que merece acompanhamento próximo. Nenhuma CVE consta atualmente no catálogo KEV da CISA, taxa abaixo da média geral do catálogo, o que sugere ausência de exploração ativa confirmada no momento — mas esse quadro não elimina o risco potencial. O maior valor EPSS observado chega a 0,98937, e a CVE mais perigosa ativa hoje, CVE-2026-10520, apresenta EPSS de 0,9894, sinalizando probabilidade muito elevada de exploração em ambiente real segundo os modelos preditivos. O tipo de falha mais recorrente é CWE-287 (falhas de autenticação), categoria que historicamente oferece superfície de ataque direta a controles de acesso e deve ser tratada com prioridade nas revisões de configuração e aplicação de patches.

CVEs

26 results
CVE-2026-10520CRITICALAn OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userEPSS 99.9%CVE-2026-10523CRITICALAn Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthentEPSS 51.9%CVE-2023-41724CRITICALA command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the EPSS 12.8%CVE-2021-47935HIGHSentry 8.2.0 Remote Code Execution via Pickle DeserializationEPSS 0.9%CVE-2023-39349HIGHSentry vulnerable to privilege escalation via ApiTokensEndpointEPSS 0.8%CVE-2023-39338MEDIUMEnables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the senEPSS 0.8%CVE-2025-53099MEDIUMSentry Missing Invalidation of Authorization Codes During OAuth Exchange and RevocationEPSS 0.7%CVE-2023-36829MEDIUMSentry CORS misconfiguration vulnerabilityEPSS 0.7%CVE-2023-36826HIGHSentry vulnerable to improper authorization on debug and artifact file downloadsEPSS 0.6%CVE-2024-53253MEDIUMSentry's improper error handling leaks Application Integration Client SecretEPSS 0.6%CVE-2026-42354CRITICALSentry: Improper authentication on SAML SSO process allows user identity linkingEPSS 0.6%CVE-2025-22146CRITICALImproper authentication on SAML SSO process allows user impersonation in sentryEPSS 0.6%CVE-2024-35196LOWSlack integration leaks sensitive information in logs in SentryEPSS 0.6%CVE-2024-24829MEDIUMSSRF in Sentry via Phabricator integrationEPSS 0.5%CVE-2024-41656HIGHSentry vulnerable to stored Cross-Site Scripting (XSS)EPSS 0.5%CVE-2026-27197CRITICALSentry: Improper Authentication on SAML SSO process allows user identity linkingEPSS 0.4%CVE-2024-32474HIGHSentry's superuser cleartext password leaked in logsEPSS 0.4%CVE-2022-23485MEDIUMInvite code reuse via cookie manipulation in sentryEPSS 0.4%CVE-2024-45605MEDIUMImproper authorization on deletion of user issue alert notifications in sentryEPSS 0.4%CVE-2024-10276MEDIUMTelestream Sentry Reports Page page cross site scriptingEPSS 0.4%