---
id: CVE-2026-10520
title: "An OS Command Injection vulnerability\_in Ivanti\_Sentry before\_the\_R10.5.2, R10.6.2 and R10.7.1\_versions\_allows\_a remote unauthenticated user to achieve root-level remote code execution"
summary: "An OS Command Injection vulnerability\_in Ivanti\_Sentry before\_the\_R10.5.2, R10.6.2 and R10.7.1\_versions\_allows\_a remote unauthenticated user to achieve root-level remote code execution"
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: ivanti
product: standalone_sentry
affected:
  - standalone_sentry < 10.5.2
  - 'standalone_sentry >= 10.6.0, < 10.6.2'
  - standalone_sentry = 10.7.0
patched:
  - standalone_sentry 10.6.2
published: '2026-06-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:35.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10520'
references:
  - url: >-
      https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US
    label: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
  - url: >-
      https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.99915
epssPercentile: 0.99968
kev: true
kevDateAdded: '2026-06-11'
kevDueDate: '2026-06-14'
kevRansomware: false
exploited: true
exploits:
  github: 7
  githubRepos:
    - >-
      https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523
    - 'https://github.com/0xBlackash/CVE-2026-10520'
    - 'https://github.com/HORKimhab/CVE-2026-10520-10523'
  nuclei:
    - CVE-2026-10520
  checkedAt: '2026-10-07T20:47:22.833Z'
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-06-12T03:55:17.049044Z'
ingestedAt: '2026-10-07T18:42:20.911Z'
---

## Overview

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

## Affected

- `standalone_sentry < 10.5.2`
- `standalone_sentry >= 10.6.0, < 10.6.2`
- `standalone_sentry = 10.7.0`

## Remediation

Upgrade past the affected range:

- `standalone_sentry 10.6.2`
