PT-2026-21350 · Sentry · Sentry
Muhammad-Qasim-Munir
·
Published
2026-02-21
·
Updated
2026-04-17
·
CVE-2026-27197
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Sentry versions 21.12.0 through 26.1.0
Description
Sentry, a developer-first error tracking and performance monitoring tool, has a critical issue in its SAML SSO implementation. This allows an attacker to take over any user account by utilizing a malicious SAML Identity Provider, particularly in a multi-organization Sentry instance. Self-hosted users are at risk if more than one organization is configured or if a malicious user has existing access and permissions to modify SSO settings for another organization. The issue allows attackers to log in as any user without a password. The vulnerability impacts account security through user identity linking.
Recommendations
Update to Sentry version 26.2.0 to resolve this issue.
Implement user account-based two-factor authentication to prevent an attacker from completing authentication with a victim's user account.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sentry