CVE-2026-10520 PUBLISHED

Assigner: ivanti
Reserved: 01.06.2026 Published: 09.06.2026 Updated: 09.06.2026

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor ivanti
Product Sentry
Versions Default: affected
  • Version R10.5.2 is unaffected
  • Version R10.6.2 is unaffected
  • Version R10.7.1 is unaffected

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-248 Command Injection