CVE-2026-42354
Sentry, a popular error‑tracking tool, had a critical flaw in its SAML SSO feature that let attackers hijack any user account if they knew the victim’s email address. The issue existed in versions 21.12.0 through 26.4.0 and was fixed in 26.4.1.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Sentry installations using SAML Single Sign‑On, specifically versions 21.12.0 up to 26.3.x.
Real-world impact
An attacker who controls a malicious SAML Identity Provider can impersonate any user on the affected Sentry instance, gaining full access to that user’s data and actions.
Why this severity
The CVSS score of 9.1 reflects a network‑based attack that requires no credentials, no user interaction, and grants complete confidentiality and integrity compromise, while availability is not affected.
What to do about it
- 01Upgrade Sentry to version 26.4.1 or later.
NVD-referenced vendor advisory
Timeline
- May 8, 2026 · May 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/getsentry/sentry/commit/0c6…patch
- github.com/getsentry/sentry/pull/11372…issue trackingpatch
- github.com/getsentry/sentry/releases/t…productrelease notes
- github.com/getsentry/sentry/security/a…mitigationvendor advisory