{"id":"CVE-2026-90999","title":"Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment","summary":"Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can su…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-20","CWE-74","CWE-94","CWE-116","CWE-913"],"vendor":"Functional Software, Inc.","product":"Sentry Seer","affected":["sentry_seer Web site"],"published":"2026-09-16","updated":"2026-09-18","sourceUpdated":"2026-09-18T17:49:08.457","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90999","references":[{"url":"https://kb.cert.org/vuls/id/212479","label":"cret@cert.org"},{"url":"https://www.kb.cert.org/vuls/id/212479","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.0067,"epssPercentile":0.49986,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-18T13:40:06.015791Z"},"ingestedAt":"2026-09-16T15:58:38.771Z","slug":"CVE-2026-90999","body":"## Overview\n\nSentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206856,"id":"CVE-2026-90999","ts":1789742636694,"field":"cvss","old":null,"new":"9.8"},{"seq":206855,"id":"CVE-2026-90999","ts":1789742636694,"field":"severity","old":"none","new":"critical"}]}