SB2026042342 - Authentication Bypass by Spoofing in sentry



SB2026042342 - Authentication Bypass by Spoofing in sentry

Published: April 23, 2026

Security Bulletin ID SB2026042342
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Authentication Bypass by Spoofing (CVE-ID: N/A)

The vulnerability allows a remote attacker to take over any user account.

The vulnerability exists due to authentication bypass by spoofing in the SAML SSO process when handling authentication with a malicious SAML identity provider across organizations on the same Sentry instance. A remote attacker can use a malicious SAML identity provider and another organization on the same Sentry instance to take over any user account.

The victim email address must be known to exploit the issue. For self-hosted deployments, exploitation requires a multi-organization instance and access to modify SSO settings for another organization.


Remediation

Install update from vendor's website.