#VU126922 Authorization bypass through user-controlled key in sentry - CVE-2024-45606
Published: September 17, 2024 / Updated: April 23, 2026
sentry
Sentry
Description
The vulnerability allows a remote attacker to mute alert rules in arbitrary organizations and projects.
The vulnerability exists due to authorization bypass through a user-controlled key in the alert rule mute request handling when processing a mute request with a known rule ID. A remote attacker can send a crafted mute request referencing another organization's or project's rule ID to mute alert rules in arbitrary organizations and projects.
The user does not need to be a member of the target organization or have permissions on the target project.