Authentication Bypass by Spoofing in sentry - CVE-2026-42354

 

Authentication Bypass by Spoofing in sentry - CVE-2026-42354

Published: April 23, 2026


Vulnerability identifier: #VU126925
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42354
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over any user account.

The vulnerability exists due to authentication bypass by spoofing in the SAML SSO process when handling authentication with a malicious SAML identity provider across organizations on the same Sentry instance. A remote attacker can use a malicious SAML identity provider and another organization on the same Sentry instance to take over any user account.

The victim email address must be known to exploit the issue. For self-hosted deployments, exploitation requires a multi-organization instance and access to modify SSO settings for another organization.


Affected software

sentry

How to mitigate CVE-2026-42354

Install security update from vendor's website.

sentry - update to 26.4.1

External References

Related Security Bulletins