PT-2026-96837 · Sentry · Sentry

CVE-2026-83803

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Sentry versions 23.11.0 through 26.6.0
Description Sentry instances with the relocation feature enabled unsafely deserialize a legacy database field during the import of a user-supplied relocation archive. An authenticated user can craft a malicious archive to achieve arbitrary code execution within the import worker process. Deserialization is the process of converting a data format, such as a file or a byte stream, back into an object that can be used by a program.
Recommendations Update to version 26.7.0. Disable the relocation feature to mitigate the risk.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-83803
GHSA-XM86-7C47-GJM4

Affected Products

Sentry