CVE-2026-27197 is a critical vulnerability in Sentry versions 21.12.0 through 26.1.0, allowing an attacker to take over any user account via a malicious SAML Identity Provider and another organization on the same Sentry instance. This vulnerability carries a CVSS score of 9.1 (CRITICAL), indicating a network-exploitable flaw with low attack complexity, leading to high confidentiality and integrity impacts. While self-hosted users are only at risk under specific multi-organization configurations, the issue has been patched in version 26.2.0, with user-enabled two-factor authentication serving as a workaround. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 21.12.0, < 26.2.0CPE matchmatch criteria | cpe:2.3:a:sentry:sentry:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.