CVE-2026-42354 Details
Description
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. This issue has been patched in version 26.4.1.
A critical vulnerability exists in Sentry's SAML Single Sign-On (SSO) implementation, affecting versions 21.12.0 prior to 26.4.1. The vulnerability allows an attacker to take over any user account by exploiting a malicious SAML Identity Provider and targeting another organization within the same Sentry instance. To successfully execute this attack, the attacker must know the victim's email address. This issue has been patched in Sentry version 26.4.1.
Users should upgrade to Sentry version 26.4.1 or later. For self-hosted Sentry instances with multiple organizations, ensure that all organizations are updated to version 26.4.1. If only a single organization is allowed, no action is needed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getsentry/sentry/commit/0c67558ae7fe08738912d4c5233b53ead048da3b | [email protected] | Patch |
| https://github.com/getsentry/sentry/pull/113720 | [email protected] | Issue TrackingPatch |
| https://github.com/getsentry/sentry/releases/tag/26.4.1 | [email protected] | ProductRelease Notes |
| https://github.com/getsentry/sentry/security/advisories/GHSA-rcmw-7mc7-3rj7 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sentry sentry | >= 21.12.0, < 26.4.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | [email protected] |