CVE-2026-10523
Awaiting Analysis Awaiting Analysis - Queue
Authentication Bypass in Ivanti Sentry

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: ivanti

Description
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-10
AI Q&A
2026-06-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
ivanti sentry to R10.5.2|end_excluding=R10.6.2|end_excluding=R10.7.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

This Authentication Bypass vulnerability allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access. Such unauthorized access can lead to exposure, modification, or deletion of sensitive data, which may result in non-compliance with data protection regulations such as GDPR and HIPAA.

Specifically, the ability to bypass authentication and gain administrative privileges undermines the security controls required to protect personal and health information, potentially violating requirements for access control, data integrity, and confidentiality mandated by these standards.

Executive Summary

This vulnerability is an Authentication Bypass (CWE-288) found in Ivanti Sentry versions before R10.5.2, R10.6.2, and R10.7.1. It allows a remote unauthenticated attacker to create arbitrary administrative accounts and gain full administrative access to the system.

Impact Analysis

The impact of this vulnerability is severe because it allows an attacker without any authentication to create administrative accounts. This means the attacker can gain full administrative control over the affected Ivanti Sentry system, potentially leading to unauthorized access, data manipulation, disruption of services, and complete compromise of the system.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10523. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart