CVE-2026-10523 PUBLISHED

Assigner: ivanti
Reserved: 01.06.2026 Published: 09.06.2026 Updated: 09.06.2026

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor ivanti
Product Sentry
Versions Default: affected
  • Version R10.5.2 is unaffected
  • Version R10.6.2 is unaffected
  • Version R10.7.1 is unaffected

References

Problem Types

  • CWE-288 Authentication bypass using an alternate path or channel CWE

Impacts

  • CAPEC-115 Authentication Bypass