CVE-2026-90999 PUBLISHED

Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

Assigner: certcc
Reserved: 14.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.

Product Status

Vendor Functional Software, Inc.
Product Sentry Seer
Versions
  • Version Web site is affected

References

Problem Types

  • CWE-20 Improper Input Validation
  • CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  • CWE-116 Improper Encoding or Escaping of Output
  • CWE-94 Improper Control of Generation of Code ('Code Injection')
  • CWE-913 Improper Control of Dynamically-Managed Code Resources