logo

Sentry’s 9.1 CVSS SSO Flaw Lets Attackers “Link” Their Way Into Your Account

ID: d1312363-24cc-5d34-b50d-00c8c780fcef

STIX ID: report--d1312363-24cc-5d34-b50d-00c8c780fcef

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Ddos

...
...

Sentry disclosed a critical SAML SSO vulnerability (CVE-2026-42354, CVSS 9.1) that permits unauthorized identity linking and potential account takeover in multi-organization Sentry instances when an attacker knows a victim's email and controls an IdP plus has permissions to modify SSO settings for at least one organization. Cloud users were auto-patched in April 2026; self-hosted instances supporting multiple organizations must upgrade to version 26.4.1 or higher. Enabling individual user 2FA prevents attackers from completing authentication even if the flaw is exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.