PT-2026-96837 · Sentry · Sentry
CVE-2026-83803
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Sentry versions 23.11.0 through 26.6.0
Description
Sentry instances with the relocation feature enabled unsafely deserialize a legacy database field during the import of a user-supplied relocation archive. An authenticated user can craft a malicious archive to achieve arbitrary code execution within the import worker process. Deserialization is the process of converting a data format, such as a file or a byte stream, back into an object that can be used by a program.
Recommendations
Update to version 26.7.0.
Disable the relocation feature to mitigate the risk.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sentry