PT-2026-47806 · Ivanti · Sentry

CVE-2026-10520

·

Published

2026-06-09

·

Updated

2026-08-24

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Sentry versions prior to R10.5.2 Ivanti Sentry versions prior to R10.6.2 Ivanti Sentry versions prior to R10.7.1
Description An OS command injection flaw allows a remote unauthenticated user to execute arbitrary code with root privileges. The issue exists in the /mics/api/v2/sentry/mics-config/handleMessage endpoint, where the message variable in a POST request is processed by the handleMessage() function in the ConfigServiceHandler.java class. When the command is set to execute, the input is passed through handleExecute() and eventually to executeNativeCommand(), which executes the string as a system shell command. Real-world exploitation attempts have been observed globally, with a significant surge in attacks targeting the technology, automotive, banking, finance, insurance, and education sectors.
Recommendations Update Ivanti Sentry to versions R10.5.2, R10.6.2, or R10.7.1 respectively. Restrict access to the /mics/api/v2/sentry/mics-config/handleMessage endpoint using WAF or IDS rules to block POST requests containing strings such as execute, system, or <commandexec> in the message parameter. Ensure the management port is not exposed to the internet.

Exploit

Fix

RCE

OS Command Injection

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08029
BDU:2026-08609
CVE-2026-10520

Affected Products

Sentry