CVE-2026-42354

critical
Published 2026-05-08 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2
VIR risk
9.8

Description

Sentry's improper authentication on SAML SSO process allows user identity linking

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/getsentry/sentry/security/advisories/GHSA-rcmw-7mc7-3rj7

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/getsentry/sentry/releases/tag/26.4.1

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/getsentry/sentry/pull/113720

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/getsentry/sentry/commit/0c67558ae7fe08738912d4c5233b53ead048da3b

Package impact

EcosystemPackageVulnerableFixed
python PyPIsentry>=21.12.0,<26.4.126.4.1
PIPsentry>= 21.12.0, <= 26.4.026.4.1

Application impact

VendorProductVersionsFixed
sentrysentry{"startIncluding":"21.12.0","endExcluding":"26.4.1"}26.4.1

References

CWEs

CWE-290

Verify integrity in audit chain (admin only). AS-IS.