← All Advisories

Ivanti Sentry Before R10.5.2 / R10.6.2 / R10.7.1 Authentication Bypass Lets Unauthenticated Remote Attackers Create Arbitrary Administrative Accounts and Obtain Full Administrative Access

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-10523

Key Details

CVECVE-2026-10523
CVSS Score / Version9.9 (Critical) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsIvanti standalone_sentry
Classified asCWE-288 (Authentication Bypass Using an Alternate Path or Channel)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Ivantistandalone_sentry
SubsystemsGeneral OT
SectorsMultiple

What to Know

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

What to Do

Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-10523
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-10523
Vendor advisoryhttps://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US