PT-2026-36821 · Sentry · Sentry
Jaydns
·
Published
2026-04-30
·
Updated
2026-05-30
·
CVE-2026-42354
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sentry versions 21.12.0 through 26.4.0
Description
A flaw in the SAML SSO implementation allows attackers to take over user accounts in multi-org instances through malicious Identity Providers. If a victim's email is known, an attacker can bypass authentication and link identities to gain unauthorized access.
Recommendations
Upgrade to version 26.4.1.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sentry