CVE-2026-26004: GHSL-2025-130: Unauthorized access to event data across organizational boundaries in Sentry - CVE-2026-26004
A cross-organization Insecure Direct Object Reference (IDOR) vulnerability has been identified in Sentry’s GroupEventJsonView endpoint.
Other sources
Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the issue.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26004?
CVE-2026-26004 has been classified as a critical vulnerability due to its potential for unauthorized access to sensitive event data.
How do I fix CVE-2026-26004?
To remediate CVE-2026-26004, upgrade Sentry to version 26.1.0 or later to eliminate the Insecure Direct Object Reference vulnerability.
What specific type of vulnerability is CVE-2026-26004?
CVE-2026-26004 is a cross-organization Insecure Direct Object Reference (IDOR) vulnerability affecting group event access.
What are the potential risks of CVE-2026-26004?
The risks of CVE-2026-26004 include unauthorized access to event data, which can lead to data breaches and loss of user privacy.
Which versions of Sentry are affected by CVE-2026-26004?
CVE-2026-26004 affects all Sentry versions prior to 26.1.0.