CVE-2026-83527: High severity Sentry sentry vulnerability
Published Sep 8, 2026
·Updated
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
Affected Software
1 affected component
Sentry sentry<10.8.2, <10.7.3, <10.6.4
Event History
Sep 8, 2026
CVE Published
via MITRE·02:36 PM
Data Sourced
via MITRE·02:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Ivanti Sentry deployments running versions earlier than R10.8.2, R10.7.3, or R10.6.4 are affected.
2
Does exploitation require credentials or user interaction?
No. The vulnerability can be exploited remotely by an unauthenticated attacker and does not require user interaction, although the attack complexity is rated high.
3
What level of access could an attacker obtain?
Successful exploitation allows an attacker to gain administrative-level access, with high potential impact to confidentiality, integrity, and availability.