Improper Authentication in sentry - #VU144312
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to take control of an authenticated user account or add themselves as an unauthorized organization member.
The vulnerability exists due to improper authentication in the SAML SSO implementation when processing SAML authentication with an attacker-controlled identity provider using a known ident value and an organization slug. A remote user can use an attacker-controlled SAML identity provider to take control of an authenticated user account or add themselves as an unauthorized organization member.
For self-hosted deployments, exploitation requires a multi-organization instance and existing access with permission to modify SSO settings for another organization. For SaaS deployments, SAML SSO must be configured.