Authentication Bypass by Spoofing
CVE-2026-42354
Summary
A critical vulnerability was discovered in the SAML SSO implementation of Sentry.The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met: They have more than one organization configured (SENTRY_SINGLE_ORGANIZATION = False). A malicious user has existing access and permissions to modify SSO settings for another organization in their multi-organization instance. The affected versions are 21.12.0 through 26.4.0.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-290 - Authentication Bypass by Spoofing
This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
References
Advisory Timeline
- Published