SB2026081972 - Improper Authentication in sentry
Published: August 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Authentication (CVE-ID: N/A)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to take control of an authenticated user account or add themselves as an unauthorized organization member.
The vulnerability exists due to improper authentication in the SAML SSO implementation when processing SAML authentication with an attacker-controlled identity provider using a known ident value and an organization slug. A remote user can use an attacker-controlled SAML identity provider to take control of an authenticated user account or add themselves as an unauthorized organization member.
For self-hosted deployments, exploitation requires a multi-organization instance and existing access with permission to modify SSO settings for another organization. For SaaS deployments, SAML SSO must be configured.
Remediation
Install update from vendor's website.