{"id":"CVE-2026-83527","title":"An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.","summary":"An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-288"],"vendor":"Ivanti","product":"Sentry","affected":["Sentry (all versions)"],"published":"2026-09-08","updated":"2026-09-09","sourceUpdated":"2026-09-09T05:18:18.923","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-83527","references":[{"url":"https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-83527","label":"3c1d8aa1-5a33-4ea4-8992-aadd6440af75"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T15:20:26.158292Z"},"ingestedAt":"2026-09-08T15:33:26.986Z","epss":0.01803,"epssPercentile":0.77576,"slug":"CVE-2026-83527","body":"## Overview\n\nAn Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}