CVE-2026-10523
This vulnerability allows attackers to create administrative accounts without authentication, giving them full control over the system. It affects Ivanti Sentry versions before R10.5.2, R10.6.2, and R10.7.1, including version 10.7.0. The issue is critical because it can be exploited remotely with minimal effort.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Ivanti Sentry standalone versions, specifically those before R10.5.2, R10.6.2, and R10.7.1, including version 10.7.0.
Real-world impact
An attacker can create admin accounts and gain full administrative access, enabling them to control the system, modify configurations, and potentially compromise data.
Why this severity
The CVSS score of 9.9 reflects the high risk of remote exploitation with low effort, low privileges, no user interaction, and full compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Ivanti Sentry to version R10.5.2 or later.
- 02Restart the Ivanti Sentry service.
NVD-referenced vendor advisory
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- hub.ivanti.com/s/article/Security-Advisory…patchvendor advisory