Skip to main content

Authentication Bypass by Spoofing

CVE-2026-42354

Severity High
Score 9.8/10

Summary

A critical vulnerability was discovered in the SAML SSO implementation of Sentry.The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met: They have more than one organization configured (SENTRY_SINGLE_ORGANIZATION = False). A malicious user has existing access and permissions to modify SSO settings for another organization in their multi-organization instance. The affected versions are 21.12.0 through 26.4.0.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-290 - Authentication Bypass by Spoofing

This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.

Advisory Timeline

  • Published