CVE-2026-42354Disclosure(sentry / sentry)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch sentry sentry systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. This issue has been patched in version 26.4.1.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sentry

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 7 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 17 signals
  • Disclosure: 10 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-30); latest day: 3
  • 19 total mentions across 7 days

Affected systems

Vendors
Products
sentry

Deep dive

Activity timeline19 mentions / 7d
01234Mentions · 2026-05-04: 3Mentions · 2026-05-06: 1Mentions · 2026-05-09: 2Mentions · 2026-05-13: 3Mentions · 2026-05-28: 3Mentions · 2026-05-30: 4Mentions · 2026-06-27: 3PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-28: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-05-28: 1Patch / Workaround · 2026-05-04: 3Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-13: 3Technical Details · 2026-05-28: 3Technical Details · 2026-05-30: 3Technical Details · 2026-06-27: 305-0405-0605-0905-1305-2805-3006-27
Signal classification5 categories
Disclosure
1052.6%
Patch
526.3%
PoC
210.5%
General
15.3%
Dis closure
15.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-043
Patch3
2026-05-061
Disclosure1
2026-05-092
Disclosure2
2026-05-133
Disclosure1General1PoC1
2026-05-283
Disclosure2PoC1
2026-05-304
Dis closure1Disclosure2Patch1
2026-06-273
Disclosure2Patch1
Full discourse19 posts
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة SSO في Sentry تم الكشف عن ثغرة أمنية خطيرة في تطبيق Sentry، منصة مراقبة التطبيقات وتتبع الأخطاء، في تنفيذ SAML SSO. تم تعقب هذه الثغرة باسم CVE-2026-42354 وتحمل درجة خطورة عالية. تسمح هذه الثغرة للمهاجمين بربط حساباتهم والحصول على الوصول غير المصرح به. استجابةً لهذا، يُنصح بتحديث الإصدارات المتأثرة ومتابعة إرشادات الشركة المصنعة. 🔗 للمزيد: https://securityonline.info/sentry-critical-sso-identity-linking-bypass-cve-2026-42354/

    Post summary

    The post announces a critical SSO vulnerability (CVE-2026-42354) affecting Sentry's SAML implementation and recommends applying vendor patches.

    000301.4K
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Vulnerability Details: CVE ID: CVE-2026-42354 CVSS Score: 9.1 (Critical) Discovery: Published May 8, 2026 Affected Versions: Sentry 21.12.0 through 26.4.0 (inclusive) Fixed In: Sentry 26.4.1 and later

    Post summary

    A critical vulnerability (CVE-2026-42354) in Sentry versions 21.12.0-26.4.0 has been disclosed, with a patch released in 26.4.1.

    1000035
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    42354, published — The SAML Shortcut: Critical Account Takeover in Sentry Allows Organization-Level Privilege Escalation. CVE-2026-42354, published May 8, 2026, is a CVSS 9.1 critical account takeover vulnerability in Sentry (error tracking/performance monitoring)…

    Post summary

    This entry announces CVE-2026-42354, a critical SAML shortcut account‑takeover flaw in Sentry with a CVSS of 9.1.

    1000051
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42354, published May 8, 2026, is a CVSS 9.1 critical account takeover vulnerability in Sentry (error tracking/performance monitoring) affecting versions 21.12.0 through 26.4.0. An attacker who controls an organization on a Sentry instance can configure a malicious…

    Post summary

    The text announces CVE-2026-42354, a critical account takeover vulnerability in Sentry affecting versions 21.12.0‑26.4.0, providing basic technical and severity details.

    1000040
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Sources DailyCVE: Sentry Improper Authentication CVE-2026-42354 GitHub Security Advisory: GHSA-rcmw-7mc7-3rj7 (Sentry SAML SSO Account Takeover) Sentry Official Release: Sentry 26.4.1 Security Patch (April 30, 2026)

    Post summary

    Sentry issued a patch (v26.4.1) for CVE‑2026‑42354 and a related SAML SSO account takeover issue (GHSA‑rcmw‑7mc7‑3rj7) as of April 30, 2026.

    1000058
    232 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR Sentry versions 21.12.0 through 26.4.0 contain a critical SAML SSO authentication bypass (CVE-2026-42354, CVSS 9.1) that allows unauthenticated attackers to take over any user account with a known email address—no credentials required. The flaw resides in how Sentry…

    Post summary

    Sentry 21.12.0–26.4.0 have a critical SAML SSO authentication bypass (CVE‑2026‑42354, CVSS 9.1) that lets attackers take over any user account via email address without credentials.

    1000049
    232 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    30, 2026. — The Identity Door Stayed Open: Sentry SAML SSO Flaw Lets Attackers Impersonate Any User Without Credentials. TL;DR Sentry versions 21.12.0 through 26.4.0 contain a critical SAML SSO authentication bypass (CVE-2026-42354, CVSS 9.1) that allows unauthenticated…

    Post summary

    The article discloses a critical SAML SSO authentication bypass (CVE-2026-42354) in Sentry 21.12.0–26.4.0 that lets attackers impersonate any user without credentials, with a CVSS score of 9.1, but it provides no PoC, exploit code, or patch details.

    1000048
    232 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sentry SAML SSO Account Takeover — CVE-2026-42354 (CRITICAL) The Authentication Wall Crumbles: Cross-Organization SAML Abuse Bypasses Every Sentry User Without Touching Their Passwords

    Post summary

    A critical Sentry SAML SSO account takeover vulnerability (CVE-2026-42354) has been disclosed, enabling cross‑organization SAML abuse to bypass user passwords. No PoC, exploit code, or mitigation details are provided.

    1000043
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42354 · 21.12.0 → 26.1.0 Sentry SAML SSO Account Takeover — CVE-2026-42354 (CRITICAL)

    Post summary

    The post announces a critical vulnerability (CVE‑2026‑42354) affecting Sentry SAML SSO that permits account takeover.

    1000041
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.1 CRITICAL · CVE-2026-42354 · 9.1 → 21.12.0 CVE: CVE-2026-42354 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑42354 as a critical vulnerability with a CVSS‑3.1 score of 9.1, without mentioning PoCs, exploits, or patches.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42354 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory Sentry is an error tracking and performance monitoring tool.

    Post summary

    The text announces a critical CVE-2026-42354 for Sentry, providing CVSS metrics and severity, but no PoC, exploit details, or patch information.

    1000041
    210 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 critical - Sentry SAML SSO Identity Linking (CVE-2026-42354) A flaw in Sentry’s SAML SSO implementation allows attackers to take over user accounts via malicious Identity Providers in multi-org instances. If the victim's email is known, an attacker can bypass authentication and link identities to gain unauthorized access. 👉 Affected: Sentry 21.12.0 - 26.4.0 | Upgrade to 26.4.1 version

    Post summary

    Sentry SAML SSO vulnerability (CVE‑2026‑42354) allows attackers to hijack user accounts via malicious IdPs in multi‑org environments, particularly when the victim’s email is known. Sentry recommends upgrading to version 26.4.1 to remediate the issue.

    0001095
    122 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Sentry | CVE-2026-42354 New vulnerability disclosed - impact depends on configuration and exposure. If you’re running Sentry: • Upgrade to patched versions • Review access and exposure • Monitor for unusual activity 🔗 https://github.com/getsentry/sentry/security/advisories/GHSA-rcmw-7mc7-3rj7

    Post summary

    Sentry releases an advisory for CVE‑2026‑42354, urging users to apply patched releases and review configuration; no exploit details or evidence of live attacks are disclosed.

    0001085
    122 followersView on X
  • Lyrie.ai@lyrie_ai
    Dis closure

    https://lyrie.ai/research/research/2026-05-02-sentry-cve-2026-42354-saml-takeover #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link points to a Lyrye AI research piece disclosing the CVE‑2026‑42354 SAML takeover vulnerability in Sentry, detailing its nature but offering no PoC, exploit code, or evidence of active exploitation.

    0000029
    232 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    https://lyrie.ai/research/research/2026-05-01-sentry-cve-2026-42354-saml-rce #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The article announces CVE‑2026‑42354, a SAML‑based remote code execution flaw in Sentry, providing proof‑of‑concept code and technical details, but does not report active exploitation or a patch.

    0000024
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    https://lyrie.ai/research/research/cve-2026-42354-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post announces CVE‑2026‑42354, supplies PoC code and technical details, but provides no patch, evidence of active exploitation, nor a debunking statement.

    0000023
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42354 Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO im… https://www.cve.org/CVERecord?id=CVE-2026-42354

    Post summary

    A new vulnerability (CVE‑2026‑42354) affecting Sentry’s SAML SSO in versions 21.12.0–26.4.1 has been disclosed, identified as a critical flaw, though no PoC, exploit, or mitigation details are provided.

    0000092
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42354 Critical Account Takeover in Sentry SAML SSO Implementation Versions 21.12.0-26.4.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42354

    Post summary

    A critical account takeover vulnerability (CVE-2026-42354) has been disclosed, affecting the Sentry SAML SSO implementation in versions 21.12.0 through 26.4.0.

    0000048
    4.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Sentry reveals a critical 9.1 CVSS flaw (CVE-2026-42354) in SAML SSO. Multi-org instances are at risk of account takeover via identity linking. Patch now! #Sentry #CVE202642354 #CyberSecurity #InfoSec #SSOBypass #IdentityHijack #IdentityLinking https://securityonline.info/sentry-critical-sso-identity-linking-bypass-cve-2026-42354/ https://t.co/cp7ykgk39p

    Post summary

    Sentry reports CVE‑2026‑42354 as a critical 9.1 CVSS flaw in SAML SSO that could enable account takeover via identity linking, and a patch is immediately available.

    00000416
    11.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsentrysentry---

Explore more