Description
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
Published: 2026-09-08
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an Authentication Bypass that allows a remote unauthenticated attacker to gain administrative level access to the Ivanti Sentry application. This weakness falls under CWE‑288, which represents problems in the authentication process that enable an attacker to bypass the intended access controls. The lack of authentication results in the attacker acquiring the full privileges of an administrator, giving them complete control over the system and its data. The impact is therefore a direct privilege escalation that can be leveraged for any number of subsequent attacks.

Affected Systems

Ivanti Sentry versions prior to R10.8.2, R10.7.3, and R10.6.4 are affected. Any deployment running those releases is vulnerable to the authentication bypass described above.

Risk and Exploitability

The CVSS score is 8.1, placing the vulnerability in the high severity range. The EPSS score is not available, but the lack of a KEV listing indicates that no known exploit has been documented in the CISA catalog. Attackers can exploit the flaw remotely without any authentication, which suggests that network exposure heightens risk. The high CVSS indicates significant potential for damage once the vulnerability is exploited.

Generated by OpenCVE AI on September 8, 2026 at 16:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Ivanti Sentry to version R10.8.2 or later, which contains the fix for the authentication bypass.
  • If an immediate upgrade is not possible, limit network access to the Sentry interfaces to trusted IP ranges and enforce strong network segmentation to reduce exposure.
  • Monitor authentication logs for anomalous patterns and consider implementing an intrusion detection system to detect potential lateral movement failures.

Generated by OpenCVE AI on September 8, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Allows Remote Unauthenticated Admin Access
First Time appeared Ivanti
Ivanti sentry
Vendors & Products Ivanti
Ivanti sentry

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-08T15:20:31.939Z

Reserved: 2026-08-31T16:19:06.248Z

Link: CVE-2026-83527

cve-icon Vulnrichment

Updated: 2026-09-08T15:20:28.913Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:51.130

Modified: 2026-09-08T16:18:17.147

Link: CVE-2026-83527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:15:15Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel