Description
Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Update
AI Analysis

Impact

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to be interpreted as executable code by an agent running in a privileged automation environment. The vulnerability essentially lets an external attacker submit fabricated Sentry events without any authentication, source repository access, or infrastructure credentials, resulting in the agent executing data that has been crafted to run in its context. This flaw exposes confidentiality, integrity, and availability of the automation system and any resources it controls.

Affected Systems

Functional Software, Inc. Sentry Seer. No specific version information is provided in the available data, so all installations of the product remain a potential target until a patch is applied or the vulnerability is mitigated.

Risk and Exploitability

The flaw carries a high potential impact, as reflected by its CVSS score of 9.8, due to the remote nature of the attack and the privilege level at which the agent operates. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that the current likelihood of exploitation in the wild is low. Nevertheless, any exposed ingestion point could be used by an attacker to introduce malicious telemetry. The likely attack vector is remote network access to the telemetry ingestion API, and the attacker does not need authentication to exploit the weakness.

Generated by OpenCVE AI on September 20, 2026 at 05:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify that a vendor‑supplied patch or newer version of Sentry Seer is available and install it without delay
  • Restrict network access to the telemetry ingestion endpoint, allowing only trusted sources or internal network traffic to reach the Sentry server
  • Configure the Sentry agent to run with the least privileges necessary, preventing it from executing code with elevated rights
  • Implement input validation and sanitization on telemetry data to detect and reject malformed or suspicious events before execution
  • Enable comprehensive logging and alerting for unauthorized or abnormal telemetry submissions to facilitate detection of attempted exploitation

Generated by OpenCVE AI on September 20, 2026 at 05:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Functional Software
Functional Software sentry Seer
Vendors & Products Functional Software
Functional Software sentry Seer

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-116
CWE-74
CWE-913
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-94

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
References

Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.
Title Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
References

Subscriptions

Functional Software Sentry Seer
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-09-18T13:40:22.164Z

Reserved: 2026-09-14T15:22:28.291Z

Link: CVE-2026-90999

cve-icon Vulnrichment

Updated: 2026-09-16T16:08:56.590Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T16:17:21.817

Modified: 2026-09-18T17:49:08.457

Link: CVE-2026-90999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-20

    Improper Input Validation

  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-913

    Improper Control of Dynamically-Managed Code Resources

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')