CVE-2026-10520: Ivanti Sentry OS Command Injection Vulnerability
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Other sources
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Sentry (formerly known as MobileIron Sentry)to a version that resolves this vulnerability.Fixed in R10.5.2 - Upgrade
Upgrade
Ivanti Sentry (formerly known as MobileIron Sentry)to a version that resolves this vulnerability.Fixed in R10.6.2 - Upgrade
Upgrade
Ivanti Sentry (formerly known as MobileIron Sentry)to a version that resolves this vulnerability.Fixed in R10.7.1 - Compensating control
Ensure the Sentry interfaces are not externally reachable: use mTLS with EPMM or restrict HTTPS access through Neurons for MDM so external actors cannot reach the interfaces.
- Compensating control
For internet-exposed assets, evaluate each asset's internet exposure and ensure Sentry appliances are not in an unmanaged state with endpoints externally reachable.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10520?
The severity of CVE-2026-10520 is rated as critical with a score of 10.
How do I fix CVE-2026-10520?
To fix CVE-2026-10520, upgrade Ivanti Sentry to versions R10.5.2, R10.6.2, or R10.7.1 or later.
What type of vulnerability is CVE-2026-10520?
CVE-2026-10520 is classified as an OS Command Injection vulnerability.
Can CVE-2026-10520 be exploited by unauthenticated users?
Yes, CVE-2026-10520 can be exploited by a remote unauthenticated user.
What can an attacker achieve by exploiting CVE-2026-10520?
An attacker exploiting CVE-2026-10520 can achieve root-level remote code execution.