CVE-2026-26004 is a cross-organization Insecure Direct Object Reference (IDOR) vulnerability affecting Sentry versions prior to 26.1.0, specifically within its GroupEventJsonView endpoint. This flaw allows an authenticated attacker with low privileges to gain unauthorized access to sensitive event data belonging to other organizations. Rated as Medium severity with a CVSS score of 6.5, the vulnerability has a network attack vector and low attack complexity, leading to a high impact on confidentiality due to data disclosure. There is currently no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB. Community attention is minimal, with only one reported media article from GitHub Security Lab detailing the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.1.0CPE matchmatch criteria | cpe:2.3:a:sentry:sentry:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.