Improper Authentication in sentry - #VU144312

 

Improper Authentication in sentry - #VU144312

Published: August 19, 2026


Vulnerability identifier: #VU144312
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to take control of an authenticated user account or add themselves as an unauthorized organization member.

The vulnerability exists due to improper authentication in the SAML SSO implementation when processing SAML authentication with an attacker-controlled identity provider using a known ident value and an organization slug. A remote user can use an attacker-controlled SAML identity provider to take control of an authenticated user account or add themselves as an unauthorized organization member.

For self-hosted deployments, exploitation requires a multi-organization instance and existing access with permission to modify SSO settings for another organization. For SaaS deployments, SAML SSO must be configured.


Affected software

sentry

Remediation

Install security update from vendor's website.

sentry - update to 26.8.0

External References

Related Security Bulletins