Misbar | مسبار[verified]@MisbarSecDisclosure
The post announces a critical SSO vulnerability (CVE-2026-42354) affecting Sentry's SAML implementation and recommends applying vendor patches.
Lyrie.ai[verified]@lyrie_aiPatch
A critical vulnerability (CVE-2026-42354) in Sentry versions 21.12.0-26.4.0 has been disclosed, with a patch released in 26.4.1.
Lyrie.ai[verified]@lyrie_aiDisclosure
This entry announces CVE-2026-42354, a critical SAML shortcut account‑takeover flaw in Sentry with a CVSS of 9.1.
Lyrie.ai[verified]@lyrie_aiDisclosure
The text announces CVE-2026-42354, a critical account takeover vulnerability in Sentry affecting versions 21.12.0‑26.4.0, providing basic technical and severity details.
Lyrie.ai[verified]@lyrie_aiPatch
Sentry issued a patch (v26.4.1) for CVE‑2026‑42354 and a related SAML SSO account takeover issue (GHSA‑rcmw‑7mc7‑3rj7) as of April 30, 2026.
Lyrie.ai[verified]@lyrie_aiDisclosure
Sentry 21.12.0–26.4.0 have a critical SAML SSO authentication bypass (CVE‑2026‑42354, CVSS 9.1) that lets attackers take over any user account via email address without credentials.
Lyrie.ai[verified]@lyrie_aiDisclosure
The article discloses a critical SAML SSO authentication bypass (CVE-2026-42354) in Sentry 21.12.0–26.4.0 that lets attackers impersonate any user without credentials, with a CVSS score of 9.1, but it provides no PoC, exploit code, or patch details.
Lyrie.ai[verified]@lyrie_aiDisclosure
A critical Sentry SAML SSO account takeover vulnerability (CVE-2026-42354) has been disclosed, enabling cross‑organization SAML abuse to bypass user passwords. No PoC, exploit code, or mitigation details are provided.