SB2026081972 - Improper Authentication in sentry



SB2026081972 - Improper Authentication in sentry

Published: August 19, 2026

Security Bulletin ID SB2026081972
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Authentication (CVE-ID: N/A)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to take control of an authenticated user account or add themselves as an unauthorized organization member.

The vulnerability exists due to improper authentication in the SAML SSO implementation when processing SAML authentication with an attacker-controlled identity provider using a known ident value and an organization slug. A remote user can use an attacker-controlled SAML identity provider to take control of an authenticated user account or add themselves as an unauthorized organization member.

For self-hosted deployments, exploitation requires a multi-organization instance and existing access with permission to modify SSO settings for another organization. For SaaS deployments, SAML SSO must be configured.


Remediation

Install update from vendor's website.