CVE-2026-90999: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
Published Sep 16, 2026
·Updated
Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.
Affected Software
1 affected component
Sentry Seer=
Event History
Sep 16, 2026
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An external, unauthenticated attacker can exploit it by submitting fabricated Sentry events. The attacker does not need access to the victim's Sentry account, source repository, or infrastructure.
2
What is the security impact of successful exploitation?
Attacker-controlled telemetry can cross a trust boundary and become code executed by an agent in a privileged automation environment.