Authentication bypass using an alternate path or channel in Ivanti Standalone Sentry - CVE-2026-10523
Published: June 10, 2026 / Updated: June 10, 2026
Ivanti Standalone Sentry
Detailed vulnerability description
The vulnerability allows a remote attacker to create arbitrary administrative accounts and obtain full administrative access.
The vulnerability exists due to an authentication bypass in Ivanti Sentry when handling authentication requests. A remote attacker can bypass authentication to create arbitrary administrative accounts and obtain full administrative access.