CVE-2026-27197Disclosure(sentry / sentry)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch sentry sentry systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. Self-hosted users are only at risk if the following criteria is met: ore than one organizations are configured (SENTRY_SINGLE_ORGANIZATION = True), or malicious user has existing access and permissions to modify SSO settings for another organization in a multo-organization instance. This issue has been fixed in version 26.2.0. To workaround this issue, implement user account-based two-factor authentication to prevent an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sentry

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 5 mentions (2026-02-22); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
sentry

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-02-22: 5Mentions · 2026-02-23: 1Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-02-22: 1Patch / Workaround · 2026-02-22: 3Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-22: 5Technical Details · 2026-02-23: 1Technical Details · 2026-04-17: 102-2202-2304-17
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-225
Disclosure3Patch2
2026-02-231
Patch1
2026-04-171
Disclosure1
Full discourse7 posts
  • Zyberwalls@ZyberWallS
    Disclosure

    Critical Auth Bypass Alert CVE-2026-27197 lets attackers log in as any user in Sentry — no password needed. If you run self-hosted Sentry, update NOW. Full breakdown: https://www.zyberwalls.com/2026/02/cve-2026-27197-sentry-login-bypass-critical-sentry.html #CVE2026 #CyberSecurity #Sentry #Infosec #ThreatIntel https://t.co/zHOJ2eBlyh

    Post summary

    CVE-2026-27197 is an authentication bypass in self-hosted Sentry that allows attackers to log in as any user without a password; users are urged to update immediately.

    0103081
    6 followersView on X
  • Zyberwalls@ZyberWallS
    Disclosure

    CVE-2026-27197 – Critical login bypass in Sentry. Attackers can log in as ANY user without a password if SSO is misconfigured. No malware. No phishing. Just broken trust. Full breakdown 👇 https://www.zyberwalls.com/2026/02/cve-2026-27197-sentry-login-bypass-critical-sentry.html #CVE2026 #CyberSecurity #Sentry #ZeroDay

    Post summary

    The post announces a critical login bypass in Sentry that allows attackers to authenticate as any user when SSO is misconfigured, with no mention of active exploitation or patches.

    0101164
    6 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Sentry, Improper Authentication, #CVE-2026-27197 (Critical) https://dailycve.com/sentry-improper-authentication-cve-2026-27197-critical/

    Post summary

    A new critical CVE-2026-27197 has been announced for Sentry, highlighting an improper authentication issue; the post lacks detailed exploitation or mitigation information.

    0000044
    181 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A critical improper authentication vulnerability in #Sentry allows attackers to hijack user accounts via a malicious identity provider. #CVE-2026-27197 CVSS: 9.1. #Patch #Patch #Patch. More info: https://github.com/getsentry/sentry/security/advisories/GHSA-ggmg-cqg6-j45g

    Post summary

    A critical improper authentication vulnerability (CVE-2026-27197) in Sentry allows attackers to hijack user accounts via a malicious identity provider; a patch is available and detailed in the linked advisory.

    00000271
    7.2K followersView on X
  • Zyberwalls@ZyberWallS
    Patch

    CVE-2026-27197 is a critical authentication bypass in Sentry that can let attackers sign in as any user — no password, no warning. If you’re running self-hosted Sentry, patch immediately. Full deep dive 👇 https://www.zyberwalls.com/2026/02/cve-2026-27197-sentry-login-bypass-critical-sentry.html #CVE2026 #CyberSecurity #SSO #Infosec

    Post summary

    The post announces a critical authentication bypass in self-hosted Sentry (CVE-2026-27197) and urges users to patch immediately, but does not provide PoC or exploit details.

    0000057
    6 followersView on X
  • The AI generalist@AIengineerlife
    Disclosure

    🚨 CVE-2026-27197 - CRITICAL Sentry (CVSS 9.1) 🤖 AI Summary: SAML SSO flaw allows attackers with malicious IdP to hijack any user account across organizations, enabling full account takeover. ThreatScore: 90/100 🔗 http://threatmonitor.io/cve/CVE-2026-27197 #cybersecurity #infosec #CVE

    Post summary

    CVE-2026-27197 is a critical SAML SSO vulnerability that allows attackers with a malicious Identity Provider to hijack user accounts across organizations, enabling full account takeover.

    0000056
    7 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Sentry` users should note CVE-2026-27197, an improper authentication flaw in the SAML SSO process. This allows user identity linking, impacting account security. Patch your `Sentry` instances. #SAML #SSO #InfoSec https://www.pulsepatch.io/posts/cve-2026-27197-sentry-saml-auth-bypass

    Post summary

    Sentry users are warned about CVE-2026-27197, an improper authentication flaw in SAML SSO that allows identity linking; a patch is recommended.

    0000050
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsentrysentry---

Explore more