PT-2026-36821 · Sentry · Sentry

·

CVE-2026-42354

·

Published

2026-04-30

·

Updated

2026-06-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sentry versions 21.12.0 through 26.4.0
Description A flaw in the SAML SSO implementation allows attackers to take over user accounts in multi-org instances through malicious Identity Providers. If a victim's email is known, an attacker can bypass authentication and link identities to gain unauthorized access.
Recommendations Upgrade to version 26.4.1.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42354
ECHO-EA50-90D1-D8B8
GHSA-RCMW-7MC7-3RJ7
PYSEC-2026-534

Affected Products

Sentry