Authentication Bypass in Sentry <= R10.8.2/ R10.7.3/ R10.6.4 (admin access)
CVE-2026-83527 Published on September 8, 2026
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
Vulnerability Analysis
CVE-2026-83527 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
Weakness Type
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Affected Versions
Ivanti Sentry:- Version R10.8.2 is unaffected.
- Version R10.7.3 is unaffected.
- Version R10.6.4 is unaffected.